CVE-2014-3743
published 2020-01-06CVE-2014-3743: Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.71%
74.9th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-marked | < node-marked 0.3.1+dfsg-1 (bookworm) | node-marked 0.3.1+dfsg-1 (bookworm) |
| marked_project | marked | < 0.3.1 | 0.3.1 |
| marked_project | marked | >= 0 < 0.3.1 | 0.3.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Multiple Content Injection Vulnerabilities in marked
ghsa·2020-08-31
CVE-2014-3743 [MEDIUM] CWE-79 Multiple Content Injection Vulnerabilities in marked
Multiple Content Injection Vulnerabilities in marked
Versions 0.3.0 and earlier of `marked` are affected by two cross-site scripting vulnerabilities, even when `sanitize: true` is set.
The attack vectors for this vulnerability are GFM Codeblocks and JavaScript URLs.
## Recommendation
Upgrade to version 0.3.1 or later.
OSV
Multiple Content Injection Vulnerabilities in marked
osv·2020-08-31
CVE-2014-3743 [MEDIUM] Multiple Content Injection Vulnerabilities in marked
Multiple Content Injection Vulnerabilities in marked
Versions 0.3.0 and earlier of `marked` are affected by two cross-site scripting vulnerabilities, even when `sanitize: true` is set.
The attack vectors for this vulnerability are GFM Codeblocks and JavaScript URLs.
## Recommendation
Upgrade to version 0.3.1 or later.
OSV
CVE-2014-3743: Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0
osv·2020-01-06·CVSS 6.1
CVE-2014-3743 [MEDIUM] CVE-2014-3743: Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.
OSV
CVE-2014-3743: Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0
osv·2020-01-06·CVSS 6.1
CVE-2014-3743 [MEDIUM] CVE-2014-3743: Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's. sanitize: true Even if this option is set, marked is vulnerable to content injection in multiple locations if untrusted user input is allowed to be provided into marked and that output is passed to the browser. Injection is possible in two locations * gfm codeblocks (language) * javascript url's
Debian
CVE-2014-3743: node-marked - Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before ...
vendor_debian·2014·CVSS 6.1
CVE-2014-3743 [MEDIUM] CVE-2014-3743: node-marked - Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before ...
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.
Scope: local
bookworm: resolved (fixed in 0.3.1+dfsg-1)
bullseye: resolved (fixed in 0.3.1+dfsg-1)
forky: resolved (fixed in 0.3.1+dfsg-1)
sid: resolved (fixed in 0.3.1+dfsg-1)
trixie: resolved (fixed in 0.3.1+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3743 marked: multiple content injection vulnerabilities [fedora-all]
bugzilla·2014-06-17·CVSS 6.1
CVE-2014-3743 [MEDIUM] CVE-2014-3743 marked: multiple content injection vulnerabilities [fedora-all]
CVE-2014-3743 marked: multiple content injection vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple
Bugzilla
CVE-2014-3743 marked: multiple content injection vulnerabilities [epel-6]
bugzilla·2014-06-17·CVSS 6.1
CVE-2014-3743 [MEDIUM] CVE-2014-3743 marked: multiple content injection vulnerabilities [epel-6]
CVE-2014-3743 marked: multiple content injection vulnerabilities [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for marked: s
Bugzilla
CVE-2014-3743 marked: multiple content injection vulnerabilities
bugzilla·2014-06-17·CVSS 6.1
CVE-2014-3743 [MEDIUM] CVE-2014-3743 marked: multiple content injection vulnerabilities
CVE-2014-3743 marked: multiple content injection vulnerabilities
Marked comes with an option to sanitize user output to help protect against content injection attacks.
...
sanitize: true
...
Even if this option is set, marked is vulnerable to content injection in multiple locations if untrusted user input is allowed to be provided into marked and that output is passed to the browser.
Injection is possible in two locations
- gfm codeblocks (language)
- javascript url's
External References:
https://nodesecurity.io/advisories/marked_multiple_content_injection_vulnerabilities
http://www.securityfocus.com/bid/67356
http://permalink.gmane.org/gmane.comp.security.oss.general/12787
Discussion:
Created marked tracking bugs for this issue:
Affects: fedora-all [bug 1110215]
Affects: epel-6
http://www.openwall.com/lists/oss-security/2014/05/13/1http://www.openwall.com/lists/oss-security/2014/05/15/2https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3743https://nodesecurity.io/advisories/marked_multiple_content_injection_vulnerabilitieshttp://www.openwall.com/lists/oss-security/2014/05/13/1http://www.openwall.com/lists/oss-security/2014/05/15/2https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3743https://nodesecurity.io/advisories/marked_multiple_content_injection_vulnerabilities
2020-01-06
Published