Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1183 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option. |
Github GHSA |
GHSA-rjqq-98f6-6j3r | Improper Input Validation in sanitize-html |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T20:26:25.401Z
Reserved: 2021-02-01T00:00:00.000Z
Link: CVE-2021-26539
No data.
Status : Modified
Published: 2021-02-08T17:15:13.673
Modified: 2024-11-21T05:56:26.517
Link: CVE-2021-26539
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA