The vendor explicitly identifies these products as affected by this CVE.
- redhat-certification-cnf.src as a component of Red Hat Certification Program for Red Hat Enterprise Linux 9
- rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub
- openshift4/ose-olm-catalogd-rhel9 as a component of Red Hat OpenShift Container Platform 4
- ansible-automation-platform/bootc-automation-portal-rhel9 as a component of Self-service automation portal 2
- Summary
- A flaw was found in Material for MkDocs. A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the search suggestion feature. A remote attacker could exploit this by crafting a malicious URL with a specially designed query parameter. After user interaction, this could lead to the execution of arbitrary JavaScript code in the context of the documentation site, potentially resulting in information disclosure or other client-side attacks.
- Remediation
- To mitigate this issue, disable the optional search.suggest feature in Material for MkDocs if it is not required for your deployment. Consult the Material for MkDocs documentation for specific configuration instructions on how to disable this feature. Disabling this feature may impact the search functionality of your documentation site.
