Open mend-bolt-for-github[bot] opened 5 years ago
The fastest markdown parser in pure Python
path: /tender_samet/requirements.txt
Library home page: https://pypi.python.org/packages/7b/ab/e71dd1ca31addcd0268c54859eaf75414a10fbc48c79078f7c3066e6ed0d/mistune-0.7.4-py2.py3-none-any.whl
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
Publish Date: 2017-12-29
URL: CVE-2017-16876
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2017-16876
Release Date: 2017-12-29
Fix Resolution: 0.8.1
Step up your Open Source Security Game with WhiteSource here
CVE-2017-16876 - Medium Severity Vulnerability
Vulnerable Library - mistune-0.7.4-py2.py3-none-any.whl
The fastest markdown parser in pure Python
path: /tender_samet/requirements.txt
Library home page: https://pypi.python.org/packages/7b/ab/e71dd1ca31addcd0268c54859eaf75414a10fbc48c79078f7c3066e6ed0d/mistune-0.7.4-py2.py3-none-any.whl
Dependency Hierarchy: - :x: **mistune-0.7.4-py2.py3-none-any.whl** (Vulnerable Library)Vulnerability Details
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
Publish Date: 2017-12-29
URL: CVE-2017-16876
CVSS 3 Score Details (6.1)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2017-16876
Release Date: 2017-12-29
Fix Resolution: 0.8.1
Step up your Open Source Security Game with WhiteSource here