CVE-2019-20903: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The hyperlinks functionality in atlaskit/editor-core in allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
References
- atlaskit.atlassian.com/packages/editor/editor-core/changelog/113.1.5
- bitbucket.org/atlassian/atlaskit-mk-2/commits/ca88f616e4
- confluence.atlassian.com/pages/viewpage.action?pageId=1021244735
- github.com/advisories/GHSA-p5ch-w78f-xh44
- nvd.nist.gov/vuln/detail/CVE-2019-20903
- www.npmjs.com/package/@atlaskit/editor-core
Detect and mitigate CVE-2019-20903 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →