Lucene search

K
osvGoogleOSV:CVE-2021-26539
HistoryFeb 08, 2021 - 5:15 p.m.

CVE-2021-26539

2021-02-0817:15:13
Google
osv.dev
7
apostrophe technologies
sanitize-html
internationalized domain names
vulnerability
whitelist validation

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

49.3%

Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the “allowedIframeHostnames” option.

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

49.3%