Description
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.
Remediation
References
http://www.openwall.com/lists/oss-security/2014/05/13/1
http://www.openwall.com/lists/oss-security/2014/05/15/2
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3743
https://nodesecurity.io/advisories/marked_multiple_content_injection_vulnerabilities
Related Vulnerabilities
CVE-2021-39148 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-43431 Vulnerability in maven package com.compuware.jenkins:compuware-strobe-measurement
CVE-2022-41940 Vulnerability in maven package org.webjars.bower:engine.io
CVE-2022-45685 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2014-3623 Vulnerability in maven package org.apache.cxf:cxf-rt-security