PT-2021-14368 · Hedgedoc · Hedgedoc

Tobias Holland

·

Published

2021-01-22

·

Updated

2021-06-08

·

CVE-2021-21259

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: HedgeDoc versions prior to 1.7.2
Description: HedgeDoc is open source software that allows users to create real-time collaborative markdown notes. An attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Depending on the configuration of the instance, the attacker may not need authentication to create or edit notes.
Recommendations: For HedgeDoc versions prior to 1.7.2, update to version 1.7.2 to resolve the issue. As a temporary workaround, consider disallowing loading JavaScript from 3rd party sites using the Content-Security-Policy header, noting that this will break some embedded content.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21259
GHSA-44W9-VM8P-3CXW

Affected Products

Hedgedoc