GHSA-wjmf-58vc-xqjr

Suggest an improvement
Source
https://github.com/advisories/GHSA-wjmf-58vc-xqjr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-wjmf-58vc-xqjr/GHSA-wjmf-58vc-xqjr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wjmf-58vc-xqjr
Withdrawn
2021-02-25T02:01:56Z
Published
2021-02-25T02:01:56Z
Modified
2021-02-25T02:01:56Z
Summary
Content injection in marked
Details

Versions 0.3.7 and earlier of marked When mangling is disabled via option mangle don't escape target href. This allow attacker to inject arbitrary html-event into resulting a tag.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-05T20:56:48Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / marked

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.3.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-wjmf-58vc-xqjr/GHSA-wjmf-58vc-xqjr.json"