CVE-2021-26539: Input Validation
Published Jan 22, 2021
·Updated
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
Affected Software
2 affected componentsFixes available
redhat/sanitize-html<2.3.1
2.3.1
apostrophecms Sanitize-html Node.js<2.3.1
Remediation
Patch Available
Event History
Jan 22, 2021
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 8, 2021
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
Description
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-26539.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain...'
3
What is the severity of CVE-2021-26539?
The severity of CVE-2021-26539 is medium with a severity value of 5.3.
4
What is the affected software for CVE-2021-26539?
The affected software for CVE-2021-26539 is Apostrophe Technologies sanitize-html before version 2.3.1.
5
How can the vulnerability be fixed?
To fix the vulnerability, upgrade to version 2.3.1 of Apostrophe Technologies sanitize-html.