XSS Vulnerability in GNOME Web Browser by GNOME
CVE-2021-45085

6.1MEDIUM

Key Information:

Vendor

Gnome

Status
Vendor
CVE Published:
16 December 2021

What is CVE-2021-45085?

An XSS vulnerability exists in the GNOME Web browser (Epiphany) prior to version 40.4 and in version 41.x prior to 41.1. This security issue can be triggered via an about: page, particularly through the 'ephy-about:overview' functionality. It becomes exploitable when a user visits a malicious page frequently enough for it to be added to the browser's Most Visited list, potentially allowing an attacker to run arbitrary scripts in the context of the user’s browser.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.