Executive brief
Docsify, a popular documentation site generator, is vulnerable to a security flaw that allows attackers to run unauthorized scripts in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could steal sensitive information like session cookies or perform actions on the user's behalf. This issue occurs because the software fails to properly clean content displayed in the sidebar and can be tricked into loading malicious files from external servers.
Technical details
Docsify before version 4.12.1 contains a Cross-Site Scripting (XSS) vulnerability that bypasses previous fixes for CVE-2020-7680. The vulnerability exists in two parts: first, while the main page content is sanitized when parsing HTML from remote URLs, the sidebar component lacks this sanitization. Second, the 'isURL' check used to identify external links can be bypassed by using multiple forward slashes (e.g., '////'). An attacker can exploit this by hosting a malicious script on a remote server and crafting a Docsify URL that points to it. When a victim visits the link, the malicious script executes in their browser context. The issue is fixed in version 4.12.1 (note: some sources mention 4.12.0, but 4.12.1 is the confirmed complete fix).
Affected products
- docsifyjs docsify < 4.12.1
Timeline
- 2021-02-18: disclosed: Vulnerability disclosed by Snyk
- 2021-02-19: advisory: NVD published CVE-2021-23342
- 2021-03-01: advisory: GitHub Advisory published
References
- https://github.com/docsifyjs/docsify/commit/ff2a66f12752471277fe81a64ad6c4b2c08111fe
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076593
- https://snyk.io/vuln/SNYK-JS-DOCSIFY-1066017
- https://www.npmjs.com/package/docsify
- http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2021/Feb/71