MEDIUM 6.1 npm
Marked vulnerable to XSS from data URIs
GHSA-7px7-7xjx-hxm8 · CVE-2017-1000427
Published · Modified
Description
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2017-1000427
- ADVISORY https://github.com/advisories/GHSA-7px7-7xjx-hxm8
- PACKAGE https://github.com/markedjs/marked
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S
- WEB https://snyk.io/vuln/npm:marked:20170112
Ready to move
Start Securing
Free, no credit card | First findings in minutes