10

CVE-2020-20269

A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CaretCaret Version <= 3.4.6
CaretCaret Version4.0.0 Updatebeta0
CaretCaret Version4.0.0 Updatebeta1
CaretCaret Version4.0.0 Updatebeta2
CaretCaret Version4.0.0 Updatebeta3
CaretCaret Version4.0.0 Updatebeta4
CaretCaret Version4.0.0 Updatebeta5
CaretCaret Version4.0.0 Updatebeta6
CaretCaret Version4.0.0 Updatebeta7
CaretCaret Version4.0.0 Updatebeta8
CaretCaret Version4.0.0 Updatebeta9
CaretCaret Version4.0.0 Updaterc1
CaretCaret Version4.0.0 Updaterc10
CaretCaret Version4.0.0 Updaterc11
CaretCaret Version4.0.0 Updaterc12
CaretCaret Version4.0.0 Updaterc13
CaretCaret Version4.0.0 Updaterc14
CaretCaret Version4.0.0 Updaterc15
CaretCaret Version4.0.0 Updaterc16
CaretCaret Version4.0.0 Updaterc17
CaretCaret Version4.0.0 Updaterc18
CaretCaret Version4.0.0 Updaterc19
CaretCaret Version4.0.0 Updaterc2
CaretCaret Version4.0.0 Updaterc20
CaretCaret Version4.0.0 Updaterc21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.69% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://packetstormsecurity.com/files/161072/Caret-Editor-4.0.0-rc21-Remote-Code-Execution.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2021/Jan/59
Third Party Advisory
Mailing List
https://caret.io
Product
https://github.com/careteditor/issues/issues/841
Third Party Advisory
Issue Tracking
https://github.com/careteditor/releases-beta/releases/tag/4.0.0-rc22
Third Party Advisory
Release Notes
https://seclists.org/fulldisclosure/2021/Jan/59
Third Party Advisory
Mailing List