MEDIUM6.1
GHSA-xmr7-v725-2jjr
Cross site scripting in comrak
Details
An issue was discovered in the comrak crate before 0.9.1 for Rust. Cross site scripting (XSS) can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/comrak
Introduced in:
0Fixed in: 0.9.1Upgrade comrak to 0.9.1 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-27671[ADVISORY]
- https://github.com/kivikakk/comrak/commit/b3efbb6e427bcd33bb14db45753ad4fd98e0f5bf[WEB]
- https://github.com/kivikakk/comrak[PACKAGE]
- https://github.com/kivikakk/comrak/releases/tag/0.9.1[WEB]
- https://rustsec.org/advisories/RUSTSEC-2021-0026.html[WEB]