Описание
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-apps/focal | released | 1.3.1-1ubuntu2+esm1 |
| esm-apps/jammy | released | 1.6.7-1ubuntu0.1~esm1 |
| esm-apps/noble | released | 2.4.2-2ubuntu0.1~esm1 |
| esm-apps/resolute | needed | |
| jammy | needed | |
| noble | needed | |
| questing | ignored | end of life, was needed |
| resolute | needed | |
| upstream | released | 2.8.2-1 |
Показывать по
Ссылки на источники
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.
league/commonmark is a PHP Markdown parser. From version 2.3.0 to befo ...
league/commonmark has an embed extension allowed_domains bypass
EPSS
6.1 Medium
CVSS3