First published: Thu Dec 16 2021(Updated: )
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/epiphany-browser | 3.32.1.2-3~deb10u1 3.32.1.2-3~deb10u3 3.38.2-1+deb11u3 43.1-1 45.0-1 | |
GNOME Epiphany | <40.4 | |
GNOME Epiphany | >=41.0<41.1 | |
Debian Debian Linux | =11.0 | |
<40.4 | ||
>=41.0<41.1 | ||
=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45086 is a Cross-Site Scripting (XSS) vulnerability that can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1.
The severity of CVE-2021-45086 is medium with a severity value of 6.1.
XSS can occur in GNOME Web because a server's suggested_filename is used as the pdf_name value in PDF.js.
Epiphany versions before 40.4 and 41.x before 41.1 are affected by CVE-2021-45086.
To mitigate the CVE-2021-45086 vulnerability, it is recommended to update GNOME Web to version 40.4 or above.