CVE-2021-44543 - log back

CVE-2021-44543 edited at 09 Dec 2021 13:52:51
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ A security issue has been found in Privoxy before version 3.0.33. cgi_error_no_template() did not encode the template name, which could lead to cross-site scripting when Privoxy is configured to servce the user-manual itself.
References
+ https://www.openwall.com/lists/oss-security/2021/12/09/1
+ https://www.privoxy.org/announce.txt
+ https://www.privoxy.org/gitweb/?p=privoxy.git;a=commitdiff;h=0e668e9409cbf4ab8bf2d79be204bd4e81a00d85
CVE-2021-44543 created at 09 Dec 2021 13:47:30