PT-2021-11237 · Mdbook · Mdbook

Kamil Vavra

·

Published

2021-01-04

·

Updated

2021-08-25

·

CVE-2020-26297

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions: mdBook versions prior to 0.4.5
Description: The search feature of mdBook is affected by a cross-site scripting vulnerability, which could allow an attacker to execute arbitrary JavaScript code on a user's browser. This can be achieved by tricking the user into typing a malicious search query or clicking a link to the search page with the malicious search query prefilled. The vulnerability was introduced in version 0.1.4 and is fixed in mdBook 0.4.5 by properly escaping the search query.
Recommendations: For mdBook versions prior to 0.4.5, upgrade to mdBook 0.4.5 or greater and rebuild website contents with it. As a temporary workaround, consider restricting access to the search feature until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26297
GHSA-GX5W-RRHP-F436
RUSTSEC-2021-0001

Affected Products

Mdbook