scriptex/github-pages-vuepress

WS-2020-0208 (Medium) detected in highlight.js-9.18.5.tgz #117

whitesource-bolt-for-github[bot] posted onGitHub

WS-2020-0208 - Medium Severity Vulnerability

<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png&#39; width=19 height=20> Vulnerable Library - <b>highlight.js-9.18.5.tgz</b></p></summary>

<p>Syntax highlighting with language autodetection.</p> <p>Library home page: <a href="https://registry.npmjs.org/highlight.js/-/highlight.js-9.18.5.tgz">https://registry.npmjs.org/highlight.js/-/highlight.js-9.18.5.tgz</a></p> <p>Path to dependency file: /package.json</p> <p>Path to vulnerable library: /node_modules/highlight.js/package.json</p> <p>

Dependency Hierarchy:

If are you are using Highlight.js to highlight user-provided data you are possibly vulnerable. On the client-side (in a browser or Electron environment) risks could include lengthy freezes or crashes... On the server-side infinite freezes could occur... effectively preventing users from accessing your app or service (ie, Denial of Service). This is an issue with grammars shipped with the parser (and potentially 3rd party grammars also), not the parser itself. If you are using Highlight.js with any of the following grammars you are vulnerable. If you are using highlightAuto to detect the language (and have any of these grammars registered) you are vulnerable.

<p>Publish Date: 2020-12-04 <p>URL: <a href=https://github.com/highlightjs/highlight.js/commit/373b9d862401162e832ce77305e49b859e110f9c>WS-2020-0208</a></p> </p> </details> <p></p> <details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png&#39; width=19 height=20> CVSS 3 Score Details (<b>5.3</b>)</summary> <p>

Base Score Metrics:

<p>Type: Upgrade version</p> <p>Origin: <a href="https://github.com/highlightjs/highlight.js/tree/10.4.1">https://github.com/highlightjs/highlight.js/tree/10.4.1</a></p> <p>Release Date: 2020-12-04</p> <p>Fix Resolution: 10.4.1</p>

</p> </details> <p></p>


Step up your Open Source Security Game with WhiteSource here


Fund this Issue

$0.00
Funded

Pull requests