PT-2021-14368 · Hedgedoc · Hedgedoc
Tobias Holland
·
Published
2021-01-22
·
Updated
2021-06-08
·
CVE-2021-21259
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
HedgeDoc versions prior to 1.7.2
Description:
HedgeDoc is open source software that allows users to create real-time collaborative markdown notes. An attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Depending on the configuration of the instance, the attacker may not need authentication to create or edit notes.
Recommendations:
For HedgeDoc versions prior to 1.7.2, update to version 1.7.2 to resolve the issue.
As a temporary workaround, consider disallowing loading JavaScript from 3rd party sites using the
Content-Security-Policy header, noting that this will break some embedded content.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hedgedoc