From 3aada4c4d8eb2bd0c11d475bfe6832b581fc443a Mon Sep 17 00:00:00 2001 From: Kohei Morita Date: Sun, 21 Feb 2021 11:22:07 +0900 Subject: [PATCH] Add advisory on comrak XSS Signed-off-by: Kohei Morita --- crates/comrak/RUSTSEC-0000-0000.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 crates/comrak/RUSTSEC-0000-0000.md diff --git a/crates/comrak/RUSTSEC-0000-0000.md b/crates/comrak/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..5e05781 --- /dev/null +++ b/crates/comrak/RUSTSEC-0000-0000.md @@ -0,0 +1,17 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "comrak" +date = "2021-02-21" +url = "https://github.com/kivikakk/comrak/releases/tag/0.9.1" +categories = ["format-injection"] +keywords = ["xss"] + +[versions] +patched = [">= 0.9.1"] +``` + +# XSS in `comrak` + +The [comrak](https://github.com/kivikakk/comrak) we were matching unsafe URL prefixes, such as `data:` or `javascript:` , in a case-sensitive manner. This meant prefixes like `Data:` were untouched. +