QID 982799
QID 982799: Python (pip) Security Update for invenio-previewer (GHSA-j9m2-6hq2-4r3c)
Security update has been released for invenio-previewer to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Several Cross-Site Scripting (XSS) vulnerabilities have been found in the JSON, Markdown and iPython Notebook previewers. The vulnerabilities would allow a malicous user to upload a JSON, Markdown or Notebook file with embedded scripts that would be executed by a victims browser.
Solution
Invenio-Previewer v1.0.0a12 fixes the issue.Workaround:
You can remediate the vulnerability without upgrading by disabling the affected previewers. You do this by adding the following to your configuration:
```python
PREVIEWER_PREFERENCE = [
'csv_dthreejs',
'simple_image',
# 'json_prismjs',
'xml_prismjs',
# 'mistune',
'pdfjs',
# 'ipynb',
'zip',
]
```
Afterwards, you should not be able to preview JSON, Markdown or iPython Notebook files.
You can remediate the vulnerability without upgrading by disabling the affected previewers. You do this by adding the following to your configuration:
```python
PREVIEWER_PREFERENCE = [
'csv_dthreejs',
'simple_image',
# 'json_prismjs',
'xml_prismjs',
# 'mistune',
'pdfjs',
# 'ipynb',
'zip',
]
```
Afterwards, you should not be able to preview JSON, Markdown or iPython Notebook files.
Vendor References
- GHSA-j9m2-6hq2-4r3c -
github.com/advisories/GHSA-j9m2-6hq2-4r3c
CVEs related to QID 982799
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j9m2-6hq2-4r3c | invenio-previewer |
|