Количество 2
Количество 2
CVE-2021-21320
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.
GHSA-52mq-6jcv-j79x
User content sandbox can be confused into opening arbitrary documents
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-21320 matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0. | CVSS3: 2.6 | 0% Низкий | почти 5 лет назад | |
GHSA-52mq-6jcv-j79x User content sandbox can be confused into opening arbitrary documents | CVSS3: 2.6 | 0% Низкий | почти 5 лет назад |
Уязвимостей на страницу