CVE-2021-39169: XSS vulnerability using dialog
Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API request token. This issue has been fixed in version 12.51.0. There are no known workarounds aside from upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Misskeyto a version that resolves this vulnerability.Fixed in 12.51.0
Event History
Frequently Asked Questions
What is CVE-2021-39169?
CVE-2021-39169 is a vulnerability that affects versions of Misskey prior to 12.51.0.
What is the severity of CVE-2021-39169?
CVE-2021-39169 has a severity rating of high.
How does CVE-2021-39169 affect Misskey?
CVE-2021-39169 allows malicious actors to display a malicious string using the web client built-in dialog, leading to cross-site scripting (XSS) and potential compromise of the API request token.
How can I fix CVE-2021-39169?
CVE-2021-39169 has been fixed in version 12.51.0 of Misskey. Please update to this version to mitigate the vulnerability.
What is the Common Weakness Enumeration (CWE) of CVE-2021-39169?
The CWE of CVE-2021-39169 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').