-
-
Notifications
You must be signed in to change notification settings - Fork 5.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Vulnerability #1477
Security Vulnerability #1477
Comments
Can you mail Snyk first regarding the vulnerability. And we will take action once there is a confirmation from them. |
Hi @anikethsaha, I can still reproduce the vulnerability with docsify version 4.12.0. By using more than two forward slashes (i.e. |
@EgidioRomano Can you use this for testing? <link rel="stylesheet" href="//cdn.jsdelivr.net/gh/sy-records/docsify-nightly/lib/themes/vue.css" />
<script src="//cdn.jsdelivr.net/gh/sy-records/docsify-nightly/lib/docsify.min.js"></script> or use https://docsify-preview.now.sh/ testing |
Hi @sy-records, My Proof of Concept doesn't work on https://docsify-preview.now.sh. |
Yes, |
If the fix is with the dev branch, is it possible to push it to master and publish a new release @sy-records? |
cc @docsifyjs/reviewers |
@sy-records I think we can release a patch on this recently, maybe next week. |
@sy-records Yes, we should push a patch release to address the security issue ASAP. |
Any update on this? thanks |
This vulnerability seems to still exist. I'm able to reproduced it against 4.13. I cannot produce it against https://docsify-preview.vercel.app/#/ (which just gives a So I think it's fixed in development? Can a new release be done? Thanks. |
@volosied I think it should have been released, can you send me the reproduction script? |
This issue was discovered by another individual. He provided the following page to test with. See here: |
yeah, I know, fixed via #2093 |
@sy-records thanks for your work! When can we expect a new release? |
Hi @henningn , I think we gonna have a patch of this asap. Hi @sy-records , could u plz raise the new release based on the last release commit as a hotfix instead of current dev branch? since we have marked changes need more clarify... if u are not free for this recently, u could ask me to do so as well. |
see #2101 |
Hi!
On December 23, 2020 I've tried to reach out to you in order to report details about a security vulnerability in Docsify.js, but I still haven't received any response to my email. Is there an appropriate channel where I should report the security issue?
The text was updated successfully, but these errors were encountered: