MEDIUM6.1
GHSA-9p29-94hp-8rvc
qiita-markdown Cross-site Scripting vulnerability
Quick fix
GHSA-9p29-94hp-8rvc — qiita-markdown: upgrade to the fixed version with the command below.
bundle update qiita-markdownDetails
Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-28796.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-28833[ADVISORY]
- https://github.com/increments/qiita-markdown/commit/b5d4e60bf537ceb177e70bf91653d29575e1aa21[WEB]
- https://github.com/increments/qiita-markdown[PACKAGE]
- https://github.com/increments/qiita-markdown/compare/v0.33.0...v0.34.0[WEB]
- https://github.com/increments/qiita-markdown/releases[WEB]
- https://vuln.ryotak.me/advisories/50[WEB]