You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
mend-for-github-combot
changed the title
WS-2019-0319 (Medium) detected in showdown-1.8.6.tgz
WS-2019-0319 (High) detected in showdown-1.8.6.tgz
Nov 20, 2020
WS-2019-0319 - High Severity Vulnerability
A Markdown to HTML converter written in Javascript
Library home page: https://registry.npmjs.org/showdown/-/showdown-1.8.6.tgz
Dependency Hierarchy:
Found in HEAD commit: 01719cf04fd7c129bd717b07454cfe760bae182e
In "showdownjs/showdown" prior to v1.9.1, 'rel="noopener' is not defined, thus can lead an attacker to control the document’s window object.
Publish Date: 2019-03-10
URL: WS-2019-0319
Base Score Metrics:
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/1302
Release Date: 2019-03-10
Fix Resolution: showdown - 1.9.1
The text was updated successfully, but these errors were encountered: