First published: Mon Nov 23 2020(Updated: )
A flaw was found in nodejs-highlight-js. Highlight.js is vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/highlight.js | <9.18.2 | 9.18.2 |
redhat/highlight.js | <10.1.2 | 10.1.2 |
Highlightjs Highlight.js Node.js | <9.18.2 | |
Highlightjs Highlight.js Node.js | >=10.1.0<10.1.2 | |
Debian Debian Linux | =9.0 | |
Oracle Mysql Enterprise Monitor | <=8.0.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.