Vulnerability CVE-2021-45087: Information

Description

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

Severity: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Published: Dec. 16, 2021
Modified: Aug. 19, 2022
Error type identifier: CWE-79

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
epiphanysisyphus41.1-alt146.0-alt1ALT-PU-2021-3546-1292090Fixed
epiphanysisyphus_riscv6441.1-alt146.0-alt1ALT-PU-2021-4608-1-Fixed
epiphanyp1040.6-alt140.6-alt1ALT-PU-2021-3624-1292094Fixed
epiphanyp10_e2k40.6-alt140.6-alt1ALT-PU-2021-4744-1-Fixed
epiphanyc10f140.6-alt140.6-alt1ALT-PU-2021-3624-1292094Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnome:epiphany:*:*:*:*:*:*:*:*
      Start including
      41.0
      End excliding
      41.1

      cpe:2.3:a:gnome:epiphany:*:*:*:*:*:*:*:*
      End excliding
      40.4

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*