Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjxr-4v3x-q3m4

Опубликовано: 06 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Input Validation in sanitize-html

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\example.com".

Пакеты

Наименование

sanitize-html

npm
Затронутые версииВерсия исправления

< 2.3.2

2.3.2

EPSS

Процентиль: 76%
0.01754
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
nvd
больше 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
debian
больше 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly v ...

EPSS

Процентиль: 76%
0.01754
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20