Milerius / tender_samet

MIT License
1 stars 4 forks source link

CVE-2017-16876 Medium Severity Vulnerability detected by WhiteSource #13

Open mend-bolt-for-github[bot] opened 5 years ago

mend-bolt-for-github[bot] commented 5 years ago

CVE-2017-16876 - Medium Severity Vulnerability

Vulnerable Library - mistune-0.7.4-py2.py3-none-any.whl

The fastest markdown parser in pure Python

path: /tender_samet/requirements.txt

Library home page: https://pypi.python.org/packages/7b/ab/e71dd1ca31addcd0268c54859eaf75414a10fbc48c79078f7c3066e6ed0d/mistune-0.7.4-py2.py3-none-any.whl

Dependency Hierarchy: - :x: **mistune-0.7.4-py2.py3-none-any.whl** (Vulnerable Library)

Vulnerability Details

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

Publish Date: 2017-12-29

URL: CVE-2017-16876

CVSS 3 Score Details (6.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2017-16876

Release Date: 2017-12-29

Fix Resolution: 0.8.1


Step up your Open Source Security Game with WhiteSource here