CVE-2021-45086: XSS
Published Dec 16, 2021
·Updated
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggestedfilename is used as the pdfname value in PDF.js.
Affected Software
4 affected componentsFixes available
debian/epiphany-browser
3.32.1.2-3~deb10u13.32.1.2-3~deb10u33.38.2-1+deb11u343.1-145.0-1
Gnome Epiphany<40.4
Gnome Epiphany>=41.0<41.1
Debian Debian Linux=11.0
Remediation
Event History
Dec 16, 2021
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-45086?
CVE-2021-45086 is a Cross-Site Scripting (XSS) vulnerability that can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1.
2
What is the severity of CVE-2021-45086?
The severity of CVE-2021-45086 is medium with a severity value of 6.1.
3
How can XSS occur in GNOME Web?
XSS can occur in GNOME Web because a server's suggested_filename is used as the pdf_name value in PDF.js.
4
Which software versions are affected by CVE-2021-45086?
Epiphany versions before 40.4 and 41.x before 41.1 are affected by CVE-2021-45086.
5
How can I mitigate the CVE-2021-45086 vulnerability in GNOME Web?
To mitigate the CVE-2021-45086 vulnerability, it is recommended to update GNOME Web to version 40.4 or above.