CVE-2021-39175

Name
CVE-2021-39175
Description
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the slides or by embedding the HedgeDoc instance into another page. The problem is patched in version 1.9.0. There are no known workarounds aside from upgrading.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/hedgedoc/hedgedoc/pull/1369
MISC https://github.com/hedgedoc/hedgedoc/pull/1513
MISC https://github.com/hedgedoc/hedgedoc/pull/1375
CONFIRM https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-j748-779h-9697

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:hedgedoc:hedgedoc:*:*:*:*:*:*:*:* hedgedoc >= None < 1.9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status