Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://research.jfrog.com/vulnerabilities/caret-xss-rce/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: JFROG
Published: 2023-01-11T00:00:00
Updated: 2024-08-03T13:19:05.492Z
Reserved: 2022-10-15T00:00:00
Link: CVE-2022-42967
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-11T13:15:09.197
Modified: 2024-11-21T07:25:42.080
Link: CVE-2022-42967
Redhat
No data.