CVE-2021-23342
Summary
| CVE | CVE-2021-23342 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-19 17:15:00 UTC |
| Updated | 2021-02-25 22:22:00 UTC |
| Description | This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more “////” characters |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: isExternal check with malformed URL + tests (#1510) · docsifyjs/docsify@ff2a66f · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Cross-site Scripting (XSS) in docsify | Snyk | MISC | snyk.io | Exploit, Third Party Advisory |
| Cross-site Scripting (XSS) in org.webjars.npm:docsify | Snyk | MISC | snyk.io | Exploit, Third Party Advisory |
| docsify 4.11.6 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory |
| Full Disclosure: [KIS-2021-02] docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: GiuliCler (Giulia Clerici)
LEGACY: Egidio Romano
Legacy QID Mappings
- 982917 Nodejs (npm) Security Update for docsify (GHSA-2mm9-c2fx-c7m4)