Vulnerability GHSA-fqx8-v33p-4qcc
Medium Risk
MEDIUM RISK
CVSS Score: 6.2
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
February 14, 2022 at 10:54 PM UTC
Cross-site Scripting in enshrined/svg-sanitize
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1
Summary
Cross-site Scripting in enshrined/svg-sanitize
Details
Impact
SVG sanitizer library before version 0.15.0 did not remove HTML elements wrapped in a CDATA section. As a result, SVG content embedded in HTML (fetched as text/html) was susceptible to cross-site scripting. Plain SVG files (fetched as image/svg+xml) were not affected.
Patches
This issue is fixed in 0.15.0 and higher.
Workarounds
There is currently no workaround available without upgrading.
For more information
If you have any questions or comments about this advisory:
- Open an issue in Github
- Email us at [email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 hours ago
enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-9rjx-3jch-6vjf
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-9rjx-3jch-6vjf
Medium Risk
4 hours ago
svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-m9xh-6747-9r6f
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-m9xh-6747-9r6f
Medium Risk
4 hours ago
enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-v383-3rw5-q8rf
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-v383-3rw5-q8rf
Medium Risk
1 year ago
svg-sanitizer Bypasses Attribute Sanitization
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0 GHSA-22wq-q86m-83fh
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0 GHSA-22wq-q86m-83fh
Medium Risk
6 years ago
Sanitizer bypass in svg-sanitizer
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0 GHSA-8rc5-hx3v-2jg7
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0 GHSA-8rc5-hx3v-2jg7
Impacted packages
Timeline
Published
4 years ago
February 14, 2022 at 10:54 PM UTC
Fixed (0.15.0)
4 years ago
February 13, 2022 at 12:42 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:20 AM UTC