MEDIUM 5.3 npm
Improper Input Validation in sanitize-html
GHSA-rjqq-98f6-6j3r · CVE-2021-26539
Published · Modified
Description
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-26539
- WEB https://github.com/apostrophecms/sanitize-html/pull/458
- WEB https://github.com/apostrophecms/sanitize-html/commit/bdf7836ef8f0e5b21f9a1aab0623ae8fcd09c1da
- WEB https://advisory.checkmarx.net/advisory/CX-2021-4308
- PACKAGE https://github.com/apostrophecms/sanitize-html
- WEB https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md#231-2021-01-22
Ready to move
Start Securing
Free, no credit card | First findings in minutes