MathJax before version 2.7.4 is vulnerable to cross-site script (XSS) injection via the \unicode macro. An attacker could exploit this to execute arbitrary Javascript in a victim's browser. External Reference: https://blog.bentkowski.info/2018/06/xss-in-google-colaboratory-csp-bypass.html Upstream Commit: https://github.com/mathjax/MathJax/commit/a55da396c18cafb767a26aa9ad96f6f4199852f1
Created mathjax tracking bugs for this issue: Affects: epel-all [bug 1608171] Affects: fedora-all [bug 1608170]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.