Lucene search

K
osvGoogleOSV:GHSA-XMR7-V725-2JJR
HistoryAug 25, 2021 - 8:52 p.m.

Cross site scripting in comrak

2021-08-2520:52:12
Google
osv.dev
5

0.001 Low

EPSS

Percentile

33.8%

An issue was discovered in the comrak crate before 0.9.1 for Rust. Cross site scripting (XSS) can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.

CPENameOperatorVersion
comraklt0.9.1

0.001 Low

EPSS

Percentile

33.8%

Related for OSV:GHSA-XMR7-V725-2JJR