Files
advisory-db/crates/comrak/RUSTSEC-2021-0026.md
Yechan Bae b724f12a5b Update CVE numbers (#777)
* Update CVE numbers

* Fix RUSTSEC-2020-0093

* Add another alias for async-h1 crate
2021-02-25 20:00:25 -05:00

486 B

[advisory]
id = "RUSTSEC-2021-0026"
package = "comrak"
aliases = ["CVE-2021-27671"]
date = "2021-02-21"
url = "https://github.com/kivikakk/comrak/releases/tag/0.9.1"
categories = ["format-injection"]
keywords = ["xss"]

[versions]
patched = [">= 0.9.1"]

XSS in comrak

The comrak we were matching unsafe URL prefixes, such as data: or javascript: , in a case-sensitive manner. This meant prefixes like Data: were untouched.