First published: Thu Dec 16 2021(Updated: )
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/epiphany-browser | <=3.32.1.2-3~deb10u1 | 3.32.1.2-3~deb10u3 3.38.2-1+deb11u3 43.1-1 45.0-1 |
GNOME Epiphany | <40.4 | |
GNOME Epiphany | >=41.0<41.1 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
<40.4 | ||
>=41.0<41.1 | ||
=10.0 | ||
=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-45087.
The severity of CVE-2021-45087 is medium (6.1).
GNOME Web (Epiphany) versions before 40.4 and 41.x before 41.1 are affected.
CVE-2021-45087 can be exploited when View Source mode or Reader mode is used, as demonstrated by a page title.
You can find more information about CVE-2021-45087 at the following references: [link1](https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612), [link2](https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045), [link3](https://security-tracker.debian.org/tracker/CVE-2021-45087).