CVE-2021-26539
08.02.2021, 17:15
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.Enginsight
Vendor | Product | Version |
---|---|---|
apostrophecms | sanitize-html | 𝑥 < 2.3.1 |
𝑥
= Vulnerable software versions

Debian Releases
References