PT-2021-18258 · Hedgedoc · Hedgedoc

Filippo Cremonese

·

Published

2021-05-19

·

Updated

2022-04-25

·

CVE-2021-29503

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: HedgeDoc versions prior to 1.8.2
Description: The issue allows an attacker with write access to a note to embed HTML tags in the Open Graph metadata section, resulting in the frontend rendering the script tag as part of the head section. This can be exploited by unauthenticated attackers if guest edits are allowed, or by authenticated attackers who have write-access to notes.
Recommendations: For HedgeDoc versions prior to 1.8.2, update to version 1.8.2 to resolve the issue. As a temporary workaround, consider disabling guest edits until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29503
GHSA-GJG7-4J2H-94FQ

Affected Products

Hedgedoc