First published: Fri Jan 29 2021(Updated: )
Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nic Foris | <101.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3346 is a vulnerability in Foris before 101.1.1, as used in Turris OS, that lacks certain HTML escaping in the login template.
CVE-2021-3346 has a severity rating of critical.
CVE-2021-3346 affects Foris version up to and exclusive of 101.1, as used in Nic Foris software.
To fix CVE-2021-3346, users should update Foris to version 101.1.1 or later.
More information about CVE-2021-3346 can be found in the following references: [Link 1](https://gitlab.nic.cz/turris/foris/foris/-/blob/master/CHANGELOG.rst), [Link 2](https://gitlab.nic.cz/turris/foris/foris/-/issues/201), [Link 3](https://www.turris.com/)