GHSA-4mvm-xh8j-fv27

Suggest an improvement
Source
https://github.com/advisories/GHSA-4mvm-xh8j-fv27
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-4mvm-xh8j-fv27/GHSA-4mvm-xh8j-fv27.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4mvm-xh8j-fv27
Withdrawn
2024-01-05T15:28:17Z
Published
2024-01-04T21:30:24Z
Modified
2026-09-10T03:50:04Z
Summary
Duplicate Advisory: govuk_tech_docs vulnerable to unescaped HTML on search results page
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-x2xw-hw8g-6773. This link is maintained to preserve external references.

Original Description

versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-01-05T15:28:17Z",
    "nvd_published_at":  "2024-01-04T21:15:09Z",
    "severity":  "LOW"
}
References

Affected packages

RubyGems / govuk_tech_docs

Package

Name
govuk_tech_docs
Purl
pkg:gem/govuk_tech_docs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.2

Affected versions

2.*
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.0.13
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
3.*
3.0.0
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.5
3.5.0
4.*
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.4.0
5.*
5.0.0
5.0.1
5.0.2
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
6.*
6.0.0.beta
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.3.0.beta
6.3.0
6.4.0.beta

Database specific

last_known_affected_version_range
"< 3.3.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-4mvm-xh8j-fv27/GHSA-4mvm-xh8j-fv27.json"