CVE-2014-3743
Summary
| CVE | CVE-2014-3743 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-06 20:15:00 UTC |
| Updated | 2020-01-13 18:52:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - CVE request: various NodeJS module vulnerabilities |
MISC |
www.openwall.com |
Mailing List, Third Party Advisory |
| 1110214 – (CVE-2014-3743) CVE-2014-3743 marked: multiple content injection vulnerabilities |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| oss-security - Re: CVE request: various NodeJS module vulnerabilities |
MISC |
www.openwall.com |
Mailing List, Third Party Advisory |
| Node Security Project | Marked multiple content injection vulnerabilities |
MISC |
nodesecurity.io |
Broken Link |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980715 Nodejs (npm) Security Update for marked (GHSA-9cw2-jqp5-7x39)