CVE-2021-23342
Last modified
CVE-2021-23342 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more “////” characters
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Docsifyjs | Docsify | < 4.12.0 |
References
- http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Feb/71Mailing List, Third Party Advisory
- https://github.com/docsifyjs/docsify/commit/ff2a66f12752471277fe81a64ad6c4b2c08111fePatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076593Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DOCSIFY-1066017Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Feb/71Mailing List, Third Party Advisory
- https://github.com/docsifyjs/docsify/commit/ff2a66f12752471277fe81a64ad6c4b2c08111fePatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076593Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DOCSIFY-1066017Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-23342?
How severe is CVE-2021-23342?
How do I fix CVE-2021-23342?
Are you affected by CVE-2021-23342?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
