CVE-2021-39286

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-39286
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-39286.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-39286
Aliases
Published
2021-08-18T18:15:08Z
Modified
2025-01-08T11:01:21.121949Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.

References

Affected packages

Git / github.com/webrecorder/pywb

Affected ranges

Type
GIT
Repo
https://github.com/webrecorder/pywb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

0.*

0.10.1
0.10.10
0.10.5
0.10.8
0.10.9
0.10.9.1
0.11.0
0.11.4
0.2.2
0.3.0
0.32.0
0.4.0
0.5.0
0.6.0
0.6.2
0.6.4
0.6.5
0.7.0
0.7.1
0.7.5
0.8.0
0.9.0
0.9.5

2.*

2.4.0-beta

v-2.*

v-2.2.20190227
v-2.2.20190311
v-2.2.20190410
v-2.3.0
v-2.3.1
v-2.4.0
v-2.4.0-beta
v-2.4.0-rc0
v-2.4.0-rc1
v-2.4.0-rc2
v-2.4.0-rc5
v-2.4.0-rc7
v-2.4.0rc4
v-2.4.1
v-2.4.2
v-2.5.0
v-2.6.0b0