Vulnerability GHSA-fqx8-v33p-4qcc

Medium Risk
MEDIUM RISK
CVSS Score: 6.2
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
February 14, 2022 at 10:54 PM UTC
Cross-site Scripting in enshrined/svg-sanitize
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1

Summary

Cross-site Scripting in enshrined/svg-sanitize

Details

Impact

SVG sanitizer library before version 0.15.0 did not remove HTML elements wrapped in a CDATA section. As a result, SVG content embedded in HTML (fetched as text/html) was susceptible to cross-site scripting. Plain SVG files (fetched as image/svg+xml) were not affected.

Patches

This issue is fixed in 0.15.0 and higher.

Workarounds

There is currently no workaround available without upgrading.

For more information

If you have any questions or comments about this advisory:

Impacted packages

Timeline

Published
4 years ago
February 14, 2022 at 10:54 PM UTC
Fixed (0.15.0)
4 years ago
February 13, 2022 at 12:42 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:20 AM UTC