Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-34473

Опубликовано: 22 дек. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 6.1

Описание

The HTML Sanitizer should have sanitized the href attribute of SVG <use> tags; however it incorrectly did not sanitize xlink:href attributes. This vulnerability affects Firefox < 102.

РелизСтатусПримечание
bionic

released

102.0+build2-0ubuntu0.18.04.1
devel

not-affected

code not present
esm-infra/focal

DNE

focal

released

102.0+build2-0ubuntu0.20.04.1
impish

released

102.0+build2-0ubuntu0.21.10.1
jammy

not-affected

code not present
kinetic

not-affected

code not present
lunar

not-affected

code not present
trusty

DNE

upstream

released

102

Показывать по

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however it incorrectly did not sanitize <code>xlink:href</code> attributes. This vulnerability affects Firefox < 102.

CVSS3: 6.1
debian
почти 3 года назад

The HTML Sanitizer should have sanitized the <code>href</code> attribu ...

CVSS3: 6.1
github
почти 3 года назад

The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however it incorrectly did not sanitize <code>xlink:href</code> attributes. This vulnerability affects Firefox < 102.

suse-cvrf
около 3 лет назад

Security update for MozillaFirefox

suse-cvrf
около 3 лет назад

Security update for MozillaFirefox

6.1 Medium

CVSS3