CVE-2021-39286: XSS
Published Aug 18, 2021
·Updated
Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.
Affected Software
2 affected componentsFixes available
Webrecorder pywb<2.6.0
pip/pywb<2.6.0
2.6.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pywbto a version that resolves this vulnerability.Fixed in 2.6.0
Event History
Aug 18, 2021
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 2, 2021
Advisory Published
via GitHub·05:16 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-39286?
The severity of CVE-2021-39286 is classified as high due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2021-39286?
To fix CVE-2021-39286, upgrade to Webrecorder pywb version 2.6.0 or later.
3
What types of attacks can occur due to CVE-2021-39286?
CVE-2021-39286 can allow attackers to execute arbitrary JavaScript code in the context of the user's session, leading to XSS attacks.
4
Which versions of Webrecorder pywb are affected by CVE-2021-39286?
All versions of Webrecorder pywb prior to 2.6.0 are affected by CVE-2021-39286.
5
Is user data at risk due to CVE-2021-39286?
Yes, user data is at risk as CVE-2021-39286 can be exploited to steal sensitive information via XSS.