First published: Fri Jan 22 2021(Updated: )
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/sanitize-html | <2.3.1 | 2.3.1 |
Apostrophecms Sanitize-html | <2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2021-26539.
The title of the vulnerability is 'Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain...'
The severity of CVE-2021-26539 is medium with a severity value of 5.3.
The affected software for CVE-2021-26539 is Apostrophe Technologies sanitize-html before version 2.3.1.
To fix the vulnerability, upgrade to version 2.3.1 of Apostrophe Technologies sanitize-html.