Vulnerability DatabaseGHSA-8fw4-xh83-3j6q

GHSA-8fw4-xh83-3j6q
JavaScript vulnerability analysis and mitigation

Overview

A Cross-Site Scripting (XSS) vulnerability was identified in diagram-js, affecting versions prior to 3.3.1 (for 3.x) and 2.6.2 (for 2.x). The vulnerability was discovered in the search-pad component where user input was not properly escaped, potentially allowing attackers to execute arbitrary JavaScript in the context of websites embedding the affected modelers (GitHub Advisory).

Technical details

The vulnerability stems from the search-pad component's failure to properly escape user-controlled input. The issue specifically affected the HTML text creation functionality where matched and normal text tokens were being directly inserted into the HTML without proper escaping. This was fixed by implementing the escapeHTML function to sanitize the user input before rendering (Diagram JS Commit).

Impact

The vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of a website embedding the affected modelers if a victim was lured into pasting crafted HTML content. The issue affected all editors for BPMN, CMMN, and DMN, though viewer distributions were not impacted (BPMN Blog).

Exploitability

The vulnerability could be exploited by convincing a user to paste specially crafted HTML content into the affected components. The search functionality and direct editing features were the primary attack vectors (BPMN Blog).

Mitigation and workarounds

Users are recommended to upgrade to the patched versions: diagram-js version 3.3.1 for 3.x users or version 2.6.2 for 2.x users. The fix involves proper HTML escaping of user input in the search-pad component (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-43309HIGH7.5
  • JavaScript logoJavaScript
  • uri-template-lite
NoYesAug 24, 2022
CVE-2022-24375HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 24, 2022
CVE-2022-25231HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 23, 2022
CVE-2022-21208HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 23, 2022
CVE-2022-2932MEDIUM6.1
  • JavaScript logoJavaScript
  • mobiledoc-kit
NoYesAug 22, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management