CVE Vulnerabilities

CVE-2021-26540

Published: Feb 08, 2021 | Modified: Apr 01, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the allowedIframeHostnames option when the allowIframeRelativeUrls is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with /example.com.

Affected Software

Name Vendor Start Version End Version
Sanitize-html Apostrophecms * 2.3.2 (excluding)
Red Hat OpenShift Container Platform 4.8 RedHat openshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream *
Red Hat OpenShift Container Platform 4.8 RedHat openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream *
Red Hat OpenShift Container Platform 4.9 RedHat openshift4/ose-prometheus:v4.9.0-202109302016.p0.git.3197fa7.assembly.stream *

References