Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjxr-4v3x-q3m4

Опубликовано: 06 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Input Validation in sanitize-html

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\example.com".

Пакеты

Наименование

sanitize-html

npm
Затронутые версииВерсия исправления

< 2.3.2

2.3.2

EPSS

Процентиль: 52%
0.00288
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
redhat
около 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
nvd
почти 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
debian
почти 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly v ...

EPSS

Процентиль: 52%
0.00288
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20