CVE-2021-38186
08.08.2021, 06:15
An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.
| Vendor | Product | Version |
|---|---|---|
| comrak_project | comrak | 𝑥 < 0.10.1 |
𝑥
= Vulnerable software versions
References