CVE Vulnerabilities

CVE-2021-26540

Published: Feb 08, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the allowedIframeHostnames option when the allowIframeRelativeUrls is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with /example.com.

Affected Software

NameVendorStart VersionEnd Version
Sanitize-htmlApostrophecms*2.3.2 (excluding)
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream*
Red Hat OpenShift Container Platform 4.9RedHatopenshift4/ose-prometheus:v4.9.0-202109302016.p0.git.3197fa7.assembly.stream*

References