Lucene search

K
freebsdFreeBSD40B481A9-9DF7-11EB-9BC3-8C164582FBAC
HistoryApr 01, 2021 - 12:00 a.m.

mdbook -- XSS in mdBook's search page

2021-04-0100:00:00
vuxml.freebsd.org
23
mdbook
xss vulnerability
search feature
version 0.4.5
security issue
javascript code

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

EPSS

0.001

Percentile

43.6%

Rust Security Response Working Group reports:

    The search feature of mdBook (introduced in version 0.1.4) was
    affected by a cross site scripting vulnerability that allowed an
    attacker to execute arbitrary JavaScript code on an user's browser
    by tricking the user into typing a malicious search query, or
    tricking the user into clicking a link to the search page with the
    malicious search query prefilled.

    mdBook 0.4.5 fixes the vulnerability by properly escaping the search
    query.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchmdbook< 0.4.5UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

EPSS

0.001

Percentile

43.6%

Related for 40B481A9-9DF7-11EB-9BC3-8C164582FBAC