CVE-2021-39175 log

Source
Severity High
Remote Yes
Type Cross-site scripting
Description
In HedgeDoc versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the slides or by embedding the HedgeDoc instance into another page.
Group Package Affected Fixed Severity Status Ticket
AVG-2331 hedgedoc 1.8.2-1 1.9.0-1 High Fixed
Date Advisory Group Package Severity Type
14 Sep 2021 ASA-202109-1 AVG-2331 hedgedoc High cross-site scripting
References
https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-j748-779h-9697
https://github.com/hedgedoc/hedgedoc/pull/1369
https://github.com/hedgedoc/hedgedoc/pull/1375
https://github.com/hedgedoc/hedgedoc/pull/1513