forked from snyk-labs/nodejs-goof
-
Notifications
You must be signed in to change notification settings - Fork 0
Closed
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
WS-2018-0031 - High Severity Vulnerability
Vulnerable Library - marked-0.3.5.tgz
A markdown parser built for speed
Library home page: https://registry.npmjs.org/marked/-/marked-0.3.5.tgz
Path to dependency file: goof/package.json
Path to vulnerable library: goof/node_modules/marked/package.json
Dependency Hierarchy:
- ❌ marked-0.3.5.tgz (Vulnerable Library)
Found in HEAD commit: b96950dc881f67b3c87181444e6a9f2234fda40d
Found in base branch: master
Vulnerability Details
The affected versions (through 0.3.5) in marked package are vulnerable to Cross-Site Scripting (XSS) Due To Sanitization Bypass Using HTML Entities
Publish Date: 2018-03-23
URL: WS-2018-0031
Suggested Fix
Type: Upgrade version
Origin: markedjs/marked#592
Release Date: 2018-03-23
Fix Resolution: 0.3.6
- Check this box to open an automated fix PR
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource