MEDIUM6.1
GHSA-f2c9-5jqw-3xh3
Cross-Site Scripting in Qiita-Markdown
Quick fix
GHSA-f2c9-5jqw-3xh3 — qiita-markdown: upgrade to the fixed version with the command below.
bundle update qiita-markdownDetails
Increments Qiita-Markdown before 0.33.0 allows XSS in transformers.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-28796[ADVISORY]
- https://github.com/advisories/GHSA-f2c9-5jqw-3xh3[ADVISORY]
- https://github.com/increments/qiita-markdown[PACKAGE]
- https://github.com/increments/qiita-markdown/compare/v0.32.0...v0.33.0[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/qiita-markdown/CVE-2021-28796.yml[WEB]
- https://vuln.ryotak.me/advisories/15[WEB]