PyPi: Mkdocs-Material

CVE-2021-40978

Transitive

Safety vulnerability ID: 59589

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Oct 07, 2021 Updated at May 17, 2024
Scan your Python projects for vulnerabilities →

Advisory

Mkdocs-material 7.3.4 updates its dependency 'mkdocs' to version '1.2.3' to include a fix for a Directory Traversal vulnerability.
https://github.com/squidfunk/mkdocs-material/commit/f9f4857af72d252b0f9c82bb95ad2131a0279bb2

Affected package

mkdocs-material

Latest version: 9.5.23

Documentation that simply works

Affected versions

Fixed versions

Vulnerability changelog

* Bumped MkDocs version to 1.2.3 to mitigate CVE-2021-40978
* Fixed spacing issues when using integrate table of contents with tabs
* Fixed some spacings issues for right-to-left languages
* Fixed race condition in search initialization

mkdocs-material-7.3.3+insiders-3.1.3 (2021-10-12)

* Added warnings to search plugin for unsupported options and syntax
* Fixed 3503: Search sometimes returns entire page
* Fixed 3089: Single-line code annotations disappear when printing

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
NONE
Availability Availability (A)
NONE

CVSS v2 Details

MEDIUM 5.0
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
NONE
Availability Impact (A)
NONE