{"id":"GHSA-98pf-gfh3-x3mp","summary":"Read the Docs vulnerable to Cross-Site Scripting (XSS)","details":"### Impact\n\nThis vulnerability allowed a malicious user to serve arbitrary HTML files from the main application domain (readthedocs[.]org/readthedocs[.]com) by exploiting a vulnerability in the code that serves downloadable content from a project. \n\nExploiting this would have required the attacker to get a logged-in user to visit the malicious URL, which would have allowed the attacker to take control of the user's session with JavaScript (making requests to the API/site on behalf of the user). This URL would have looked something like `hxxps[:]//readthedocs[.]org/projects/attacker-project/downloads/html/version-with-javascript-attack/`.\n\n### Patches\n\nThis issue has been patched in our 8.8.1 release.","modified":"2022-11-10T16:02:51Z","published":"2022-11-10T16:02:51Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-10T16:02:51Z"},"references":[{"type":"WEB","url":"https://github.com/readthedocs/readthedocs.org/security/advisories/GHSA-98pf-gfh3-x3mp"},{"type":"WEB","url":"https://github.com/readthedocs/readthedocs.org/commit/b0ae626acd13882170ec5888e35f3ef2e48e6ff6"},{"type":"PACKAGE","url":"https://github.com/readthedocs/readthedocs.org"}],"affected":[{"package":{"name":"readthedocs","ecosystem":"npm","purl":"pkg:npm/readthedocs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-98pf-gfh3-x3mp/GHSA-98pf-gfh3-x3mp.json"}}],"schema_version":"1.9.0"}