Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the allowedIframeHostnames option.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sanitize-html | Apostrophecms | * | 2.3.1 (excluding) |
Red Hat OpenShift Container Platform 4.7 | RedHat | openshift4/ose-console:v4.7.0-202102130115.p0 | * |
Red Hat OpenShift Container Platform 4.8 | RedHat | openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream | * |
Red Hat OpenShift Container Platform 4.9 | RedHat | openshift4/ose-prometheus:v4.9.0-202109302016.p0.git.3197fa7.assembly.stream | * |