Описание
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| tt-rss | fixed | 21~git20210204.b4cbc79+dfsg-1 | package | |
| tt-rss | no-dsa | buster | package |
Примечания
https://community.tt-rss.org/t/heads-up-several-vulnerabilities-fixed/3799
https://git.tt-rss.org/fox/tt-rss/commit/da5af2fae091041cca27b24b6f0e69e4a6d0dc60
EPSS
Процентиль: 67%
0.00528
Низкий
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 5 лет назад
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVSS3: 6.1
nvd
больше 5 лет назад
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVSS3: 6.1
github
больше 3 лет назад
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
EPSS
Процентиль: 67%
0.00528
Низкий