GHSA-xgfm-fjx6-62mj

    Dashboard / Vulnerabilities / GHSA-xgfm-fjx6-62mj

    GHSA-xgfm-fjx6-62mj

    Published: 16 Jan 2024Last Modified: 28 Nov 2024

    Summary: readthedocs-sphinx-search vulnerable to cross-site scripting when including search results from malicious projects

    Details: ### Impact This vulnerability could have allowed an attacker to include arbitrary HTML content in search results by having a user search a malicious project. This was due to our search client not correctly escaping all user content from search results. You can find more information in the [advisory published in our readthedocs.org repo](https://github.com/readthedocs/readthedocs.org/security/advisories/GHSA-qhqx-5j25-rv48). Users of this extension should update to the 0.3.2 version, and trigger a new build. This issue was discovered by a member of our team, and we have seen no signs that this vulnerability was exploited in the wild. ### Patches This issue has been patched in our 0.3.2 version. ### References - https://github.com/readthedocs/readthedocs-sphinx-search/commit/8c6f6d01e88e72ef32ed0c220b6c19d1e1121c73 ### For more information If you have any questions or comments about this advisory, email us at [[email protected]](mailto:[email protected]) ([PGP](https://docs.readthedocs.io/page/security.html#pgp-key))

    Affected packages

    Package

    Name: readthedocs-sphinx-search

    Purl: pkg:pypi/readthedocs-sphinx-search

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.3.2

    Affected versions

    0.1.0
    0.1.0rc1
    0.1.0rc2
    0.1.0rc3
    0.1.1
    0.1.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-xgfm-fjx6-62mj | CVE-DB