CVE-2021-45088: XSS
Published Dec 16, 2021
·Updated
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
Affected Software
5 affected componentsFixes available
debian/epiphany-browser<=3.32.1.2-3~deb10u1
3.32.1.2-3~deb10u33.38.2-1+deb11u343.1-145.0-1
Gnome Epiphany<40.4
Gnome Epiphany>=41.0<41.1
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Dec 16, 2021
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-45088?
CVE-2021-45088 is a vulnerability that allows cross-site scripting (XSS) attacks to occur in GNOME Web (Epiphany) before version 40.4 and 41.x before 41.1 via an error page.
2
How severe is CVE-2021-45088?
CVE-2021-45088 has a severity level of medium with a CVSS score of 6.1.
3
How does CVE-2021-45088 affect GNOME Web (Epiphany)?
CVE-2021-45088 affects GNOME Web (Epiphany) before version 40.4 and 41.x before 41.1.
4
What is the affected software version of GNOME Web (Epiphany)?
The affected software versions of GNOME Web (Epiphany) range from before 40.4 to 41.x before 41.1.
5
How can I fix CVE-2021-45088?
To fix CVE-2021-45088, update GNOME Web (Epiphany) to version 40.4 or 41.1.