OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:34
发布时间
2020-09-02 05:25
GitHub 审查时间
2020-09-01 02:34
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-mpjf-8cmf-p789/GHSA-mpjf-8cmf-p789.json
Versions of jingo prior to 1.9.2 are vulnerable to Cross-Site Scripting (XSS). If malicious input such as <script>alert(1)</script> is placed in the content of a wiki page, Jingo does not properly encode the input and it is executed instead of rendered as text.
Upgrade to version 1.9.2