CVE-2015-3295: Medium severity markdown it for python (markdown-it-py) vulnerability
Published Jun 7, 2017
·Updated
markdown-it before 4.1.0 does not block data: URLs.
Affected Software
1 affected component
Markdown-it Project Markdown-it=4.0.3
Remediation
Event History
Jun 7, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3295?
CVE-2015-3295 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-3295?
To address CVE-2015-3295, update to version 4.1.0 or later of markdown-it.
3
What type of vulnerability is CVE-2015-3295?
CVE-2015-3295 is a security issue related to the improper handling of data URLs.
4
Which versions are affected by CVE-2015-3295?
CVE-2015-3295 affects markdown-it versions prior to 4.1.0, specifically version 4.0.3.
5
Can CVE-2015-3295 allow for remote code execution?
CVE-2015-3295 does not directly enable remote code execution, but can lead to potential security risks through unsafe data handling.