-
Notifications
You must be signed in to change notification settings - Fork 16
Open
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
CVE-2021-35513 - Medium Severity Vulnerability
Vulnerable Library - mermaid-8.8.1.min.js
Markdownish syntax for generating flowcharts, sequence diagrams, class diagrams and gantt charts.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.8.1/mermaid.min.js
Path to dependency file: /docs-src/themes/tibcolabs/layouts/partials/scripts.html
Path to vulnerable library: /docs-src/themes/tibcolabs/layouts/partials/scripts.html
Dependency Hierarchy:
- ❌ mermaid-8.8.1.min.js (Vulnerable Library)
Found in HEAD commit: 2b36f19c6531f1a3964d83923e752838cd9d62cb
Found in base branch: master
Vulnerability Details
Mermaid before 8.11.0 allows XSS when the antiscript feature is used.
Publish Date: 2021-06-27
URL: CVE-2021-35513
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-4f6x-49g2-99fm
Release Date: 2021-06-27
Fix Resolution: mermaid - 8.11.0
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource