CVE-2021-38186: Cross-site Scripting in comrak
An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.
References
- github.com/advisories/GHSA-6wj2-g87r-pm62
- github.com/kivikakk/comrak
- github.com/kivikakk/comrak/commit/b72340cabe4749952530b4fb6b4fcc706bc973e5
- github.com/kivikakk/comrak/compare/0.10.0...0.10.1
- github.com/kivikakk/comrak/releases/tag/0.10.1
- nvd.nist.gov/vuln/detail/CVE-2021-38186
- rustsec.org/advisories/RUSTSEC-2021-0063.html
Detect and mitigate CVE-2021-38186 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →