[GHSA-rpr9-rxv7-x643] Apostrophe has default XSS via xmp raw-text passthrough in sanitize-html#7696
Conversation
|
Hi there @boutell! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
Hi there @boutell! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
Updates
Comments
The issue is only introduced in the version 2.17.3, and patched in the new version 2.17.4. More info here apostrophecms/apostrophe#5418