A flaw was found in marked, a markdown parser and compiler used for rendering markdown content to html. Affected versions of the package are vulnerable to Cross-site Scripting (XSS) attacks. Browsers support both lowercase and uppercase x in hexadecimal form of HTML character entity, but marked unescaped only lowercase. [UPSTREAM BUG] https://github.com/chjj/marked/issues/925 [UPSTREAM PATCH] https://github.com/UziTech/marked/commit/6d1901ff71abb83aa32ca9a5ce47471382ea42a9
Created marked tracking bugs for this issue: Affects: epel-all [bug 1529730] Affects: fedora-all [bug 1529729]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.