CVE-2017-1000427Cross-site Scripting in Node-marked

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 40.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateJan 4

Description

marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

debiandebian/node-marked< node-marked 0.3.9+dfsg-1 (bookworm)

Patches

🔴Vulnerability Details

3
OSV
Marked vulnerable to XSS from data URIs2018-01-04
GHSA
Marked vulnerable to XSS from data URIs2018-01-04
OSV
CVE-2017-1000427: marked version 02018-01-02

📋Vendor Advisories

1
Debian
CVE-2017-1000427: node-marked - marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI...2017

💬Community

4
Bugzilla
CVE-2017-1000427 marked: Cross-site scripting via Data URIs2017-01-31
Bugzilla
CVE-2017-1000427 marked: Cross-site scripting via Data URIs [epel-7]2017-01-31
Bugzilla
CVE-2017-1000427 marked: Cross-site scripting via Data URIs [epel-6]2017-01-31
Bugzilla
CVE-2017-1000427 marked: Cross-site scripting via Data URIs [fedora-all]2017-01-31