The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://confluence.atlassian.com/pages/viewpage.action?pageId=1021244735 | vendor advisory |
https://atlaskit.atlassian.com/packages/editor/editor-core/changelog/113.1.5 | release notes vendor advisory |
https://www.npmjs.com/package/%40atlaskit/editor-core |