QID 982917
QID 982917: Nodejs (npm) Security Update for docsify (GHSA-2mm9-c2fx-c7m4)
This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more //// characters
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2mm9-c2fx-c7m4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2mm9-c2fx-c7m4 -
github.com/advisories/GHSA-2mm9-c2fx-c7m4
CVEs related to QID 982917
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2mm9-c2fx-c7m4 | docsify |
|