Lucene search

K
rustsecRustsecRUSTSEC-2021-0026
HistoryFeb 21, 2021 - 12:00 p.m.

XSS in `comrak`

2021-02-2112:00:00
rustsec.org
5

0.001 Low

EPSS

Percentile

33.8%

The comrak we were matching unsafe URL prefixes, such as data: or javascript: , in a case-sensitive manner. This meant prefixes like Data: were untouched.

CPENameOperatorVersion
comraklt0.9.1

0.001 Low

EPSS

Percentile

33.8%

Related for RUSTSEC-2021-0026