9.8
CVE-2021-42576
- EPSS 1.56%
- Veröffentlicht 18.10.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:50
- Erkennungen
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microco ≫ Bluemonday SwPlatform go Version < 1.0.16
Python ≫ Pybluemonday Version < 0.0.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.56% | 0.73 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/