Wind River Support Network

HomeDefectsLIN1021-2224
Fixed

LIN1021-2224 : Security Advisory - epiphany - CVE-2021-45085

Created: Dec 16, 2021    Updated: Apr 26, 2022
Resolved Date: Apr 26, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.12
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.

CREATE(Triage):(User=admin) CVE-2021-45085 (https://nvd.nist.gov/vuln/detail/CVE-2021-45085)

CVEs


Live chat
Online