VDB
CVE-2021-45087
CVE-2021-45087
PUBLISHED
CVSS 6.099999904632568 MEDIUM
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
EPSS 1.50% · 72.4th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.50%
72.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| debian | debian_linux | 10.0, 11.0 |
| gnome | epiphany | 0, 41.0 |
Timeline
- Dec 16, 2021 EPSS Score
- Dec 16, 2021 CVE Published
- Feb 8, 2022 EPSS Score
- Apr 4, 2022 EPSS Score
- May 28, 2022 EPSS Score
- Sep 15, 2022 EPSS Score
- Nov 9, 2022 EPSS Score
- Jan 2, 2023 EPSS Score
- Feb 26, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 21, 2023 EPSS Score
- Jun 15, 2023 EPSS Score
References
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045 url
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612 url
- DSA-5042 vendor-advisory
- [debian-lts-announce] 20220818 [SECURITY] [DLA 3074-1] epiphany-browser security update mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2021-45087 advisory