Bugzilla – Bug 1193827
VUL-0: CVE-2021-45085: epiphany: XSS in about page
Last modified: 2021-12-16 16:15:02 UTC
CVE-2021-45085 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45085 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45085 https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045 https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612