QID 982575
QID 982575: Go (go) Security Update for github.com/documize/community/domain/section/markdown (GHSA-wmwp-pggc-h4mj)
domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wmwp-pggc-h4mj for updates pertaining to this vulnerability.
Vendor References
- GHSA-wmwp-pggc-h4mj -
github.com/advisories/GHSA-wmwp-pggc-h4mj
CVEs related to QID 982575
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wmwp-pggc-h4mj | github.com/documize/community |
|
|
| GHSA-wmwp-pggc-h4mj | github.com/documize/community/domain/section/markdown |
|