Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array).
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Vulnerability Title
do-markdownit 安全漏洞
Vulnerability Description
do-markdownit是DigitalOcean开源的一个插件。 do-markdownit 1.16.1及之前版本存在安全漏洞,该漏洞源于callout和fence_environment插件对allowedClasses或allowedEnvironments执行.includes子字符串匹配,可能导致安全绕过。
CVSS Information
N/A
Vulnerability Type
N/A