Description
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
Remediation
References
https://snyk.io/vuln/npm:marked:20170112
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S/
Related Vulnerabilities
CVE-2022-29172 Vulnerability in maven package org.webjars.npm:auth0-lock
CVE-2022-40150 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2020-13943 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2014-7192 Vulnerability in npm package syntax-error
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-standard-processors