Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-26540

Опубликовано: 08 фев. 2021
Источник: debian
EPSS Низкий

Описание

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-sanitize-htmlnot-affectedpackage

EPSS

Процентиль: 76%
0.01754
Низкий

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
nvd
больше 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
github
больше 5 лет назад

Improper Input Validation in sanitize-html

EPSS

Процентиль: 76%
0.01754
Низкий