PT-2021-18258 · Hedgedoc · Hedgedoc
Filippo Cremonese
·
Published
2021-05-19
·
Updated
2022-04-25
·
CVE-2021-29503
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
HedgeDoc versions prior to 1.8.2
Description:
The issue allows an attacker with write access to a note to embed HTML tags in the Open Graph metadata section, resulting in the frontend rendering the script tag as part of the head section. This can be exploited by unauthenticated attackers if guest edits are allowed, or by authenticated attackers who have write-access to notes.
Recommendations:
For HedgeDoc versions prior to 1.8.2, update to version 1.8.2 to resolve the issue. As a temporary workaround, consider disabling guest edits until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hedgedoc