CVE-2021-45085: XSS
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45085?
CVE-2021-45085 is a vulnerability that allows for cross-site scripting (XSS) attacks in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an "about:" page.
How does CVE-2021-45085 occur?
CVE-2021-45085 occurs when a user visits an XSS payload page often enough to place that page on the Most Visited list of GNOME Web.
What is the severity of CVE-2021-45085?
The severity of CVE-2021-45085 is medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2021-45085?
GNOME Web (Epiphany) versions before 40.4 and versions 41.x before 41.1 are affected by CVE-2021-45085.
How can I fix CVE-2021-45085?
To fix CVE-2021-45085, users should update GNOME Web (Epiphany) to version 40.4 or 41.1 or a later version.