CVE-2021-29979: XSS
Published Jul 14, 2021
·Updated
Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s primary hosting domain.
Affected Software
2 affected componentsFixes available
Mozilla Hubs Cloud
Mozilla Hubs Cloud mozillareality/reticulum//20210618012634<1.0.1
1.0.1
Event History
Jul 14, 2021
CVE Published
12:00 AM
Aug 2, 2021
CVE Published
via MITRE·08:45 PM
Data Sourced
via MITRE·08:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29979?
CVE-2021-29979 is classified as a high severity vulnerability due to its potential for JavaScript execution in the hosting domain.
2
How do I fix CVE-2021-29979?
To fix CVE-2021-29979, update your Hubs Cloud software to version 1.0.1 or later.
3
What causes CVE-2021-29979?
CVE-2021-29979 is caused by the ability of users to download shared HTML and JavaScript content that can execute in the primary hosting domain.
4
Which versions of Hubs Cloud are affected by CVE-2021-29979?
Hubs Cloud versions prior to 1.0.1 are affected by CVE-2021-29979.
5
Is CVE-2021-29979 under active exploitation?
There is no public indication that CVE-2021-29979 is currently under active exploitation.