VDB
Sign up
MEDIUM6.1

GHSA-9p29-94hp-8rvc

qiita-markdown Cross-site Scripting vulnerability

Quick fix

GHSA-9p29-94hp-8rvc — qiita-markdown: upgrade to the fixed version with the command below.

bundle update qiita-markdown

Details

Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-28796.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/qiita-markdown
Introduced in: 0Fixed in: 0.34.0
Fixbundle update qiita-markdown

References