First published: Thu Dec 16 2021(Updated: )
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/epiphany-browser | <=3.32.1.2-3~deb10u1 | 3.32.1.2-3~deb10u3 3.38.2-1+deb11u3 43.1-1 45.0-1 |
GNOME Epiphany | <40.4 | |
GNOME Epiphany | >=41.0<41.1 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45085 is a vulnerability that allows for cross-site scripting (XSS) attacks in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an "about:" page.
CVE-2021-45085 occurs when a user visits an XSS payload page often enough to place that page on the Most Visited list of GNOME Web.
The severity of CVE-2021-45085 is medium with a CVSS score of 6.1.
GNOME Web (Epiphany) versions before 40.4 and versions 41.x before 41.1 are affected by CVE-2021-45085.
To fix CVE-2021-45085, users should update GNOME Web (Epiphany) to version 40.4 or 41.1 or a later version.