Open mend-for-github-com[bot] opened 2 years ago
The HTML Presentation Framework
Library home page: https://cdnjs.cloudflare.com/ajax/libs/reveal.js/2.4.0/js/reveal.js
Path to vulnerable library: /src/cpp/session/resources/presentation/revealjs/js/reveal.js
Dependency Hierarchy: - :x: **reveal-2.4.0.js** (Vulnerable Library)
Found in HEAD commit: b3d036e0cb4bcb5dd4823827a94b172341b2b069
Found in base branch: main
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
Publish Date: 2020-02-28
URL: CVE-2020-8127
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8127
Release Date: 2020-03-03
Fix Resolution: reveal.js - 3.9.2
CVE-2020-8127 - Medium Severity Vulnerability
Vulnerable Library - reveal-2.4.0.js
The HTML Presentation Framework
Library home page: https://cdnjs.cloudflare.com/ajax/libs/reveal.js/2.4.0/js/reveal.js
Path to vulnerable library: /src/cpp/session/resources/presentation/revealjs/js/reveal.js
Dependency Hierarchy: - :x: **reveal-2.4.0.js** (Vulnerable Library)
Found in HEAD commit: b3d036e0cb4bcb5dd4823827a94b172341b2b069
Found in base branch: main
Vulnerability Details
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
Publish Date: 2020-02-28
URL: CVE-2020-8127
CVSS 3 Score Details (6.1)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8127
Release Date: 2020-03-03
Fix Resolution: reveal.js - 3.9.2