Description
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
Remediation
References
https://confluence.atlassian.com/pages/viewpage.action?pageId=1021244735
https://atlaskit.atlassian.com/packages/editor/editor-core/changelog/113.1.5
https://www.npmjs.com/package/%40atlaskit/editor-core
Related Vulnerabilities
CVE-2018-5158 Vulnerability in maven package org.webjars.bower:pdfjs-dist
CVE-2021-1626 Vulnerability in maven package org.mule.runtime:mule-core
CVE-2023-42795 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-45105 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2011-2731 Vulnerability in maven package org.springframework.security:spring-security-core