Cross-site scripting in sanitize-url - CVE-2021-23648
Published: August 30, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in sanitizeUrl() function. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Oracle Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
OpenShift Service Mesh
Red Hat OpenShift Container Platform
grafana
grafana (Red Hat package)
How to mitigate CVE-2021-23648
OpenShift Service Mesh - update to 2.3.1
Red Hat OpenShift Container Platform - update to 4.11.0
grafana - addressed in versions 7.5.15-2.fc34, 7.5.15-2.fc35, 7.5.15-2.fc36
grafana (Red Hat package) - addressed in versions 7.5.15-3.el8, 7.5.15-3.el9
External References
- https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882
- https://github.com/braintree/sanitize-url/pull/40
- https://github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183
- https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/
Related Security Bulletins
- XSS in sanitize-url
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Multiple vulnerabilities in Oracle Linux
- Fedora 36 update for grafana
- Fedora 35 update for grafana
- Fedora 34 update for grafana