You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In mermaid, versions prior to 8.2.3 are vulnerable to Cross-Site Scripting if malicious input is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.
mend-for-github-combot
changed the title
WS-2019-0255 (Medium) detected in mermaid-8.0.0-rc.8.min.js, mermaid-8.0.0-rc.8.js
WS-2019-0255 (Medium) detected in multiple libraries
Sep 15, 2022
WS-2019-0255 - Medium Severity Vulnerability
Vulnerable Libraries - mermaid.core-8.0.0-rc.8.js, mermaid-8.0.0-rc.8.min.js, mermaid-8.0.0-rc.8.js
mermaid.core-8.0.0-rc.8.js
Markdownish syntax for generating flowcharts, sequence diagrams, class diagrams and gantt charts.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.0.0-rc.8/mermaid.core.js
Path to vulnerable library: /public/mermaid/mermaid.core.js
Dependency Hierarchy:
mermaid-8.0.0-rc.8.min.js
Markdownish syntax for generating flowcharts, sequence diagrams, class diagrams and gantt charts.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.0.0-rc.8/mermaid.min.js
Path to vulnerable library: /public/mermaid/mermaid.min.js
Dependency Hierarchy:
mermaid-8.0.0-rc.8.js
Markdownish syntax for generating flowcharts, sequence diagrams, class diagrams and gantt charts.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.0.0-rc.8/mermaid.js
Path to vulnerable library: /public/mermaid/mermaid.js
Dependency Hierarchy:
Found in HEAD commit: 86334f0df744f6cfa35a438987cbb4d18d65b5c2
Found in base branch: master
Vulnerability Details
In mermaid, versions prior to 8.2.3 are vulnerable to Cross-Site Scripting if malicious input is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.
Publish Date: 2019-07-22
URL: WS-2019-0255
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/751
Release Date: 2019-07-22
Fix Resolution: 8.2.3
The text was updated successfully, but these errors were encountered: