Lucene search

K
osvGoogleOSV:GHSA-RJQQ-98F6-6J3R
HistoryMay 06, 2021 - 4:10 p.m.

Improper Input Validation in sanitize-html

2021-05-0616:10:05
Google
osv.dev
8
apostrophe technologies
sanitize-html
input validation
hostname whitelist
idn
attacker
software security

EPSS

0.001

Percentile

49.3%

Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the “allowedIframeHostnames” option.

EPSS

0.001

Percentile

49.3%