Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1
Описание
Cross-site scripting in Unicorn framework
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-42053
- https://github.com/adamghill/django-unicorn/pull/288
- https://github.com/adamghill/django-unicorn/commit/aa5b9835d946bd9893ef02e556859e3ea62cc5e2
- https://github.com/adamghill/django-unicorn/compare/0.35.3...0.36.0
- https://github.com/advisories/GHSA-c87f-fq5g-63r2
- https://github.com/pypa/advisory-database/tree/main/vulns/django-unicorn/PYSEC-2021-357.yaml
- http://packetstormsecurity.com/files/164442/django-unicorn-0.35.3-Cross-Site-Scripting.html
Пакеты
Наименование
django-unicorn
pip
Затронутые версииВерсия исправления
< 0.36.0
0.36.0
Связанные уязвимости
CVSS3: 5.4
nvd
больше 4 лет назад
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.