9.8
CVE-2021-42576
- EPSS 0.32%
- Veröffentlicht 18.10.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:50
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microco ≫ Bluemonday SwPlatformgo Version < 1.0.16
Python ≫ Pybluemonday Version < 0.0.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.546 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|