QID 981560
QID 981560: Python (pip) Security Update for markdown2 (GHSA-fv3h-8x5j-pvgq)
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fv3h-8x5j-pvgq for updates pertaining to this vulnerability.
Vendor References
- GHSA-fv3h-8x5j-pvgq -
github.com/advisories/GHSA-fv3h-8x5j-pvgq
CVEs related to QID 981560
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fv3h-8x5j-pvgq | markdown2 |
|