CVE-2021-3346: Critical severity nic Foris vulnerability
Published Jan 29, 2021
·Updated
Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.
Affected Software
1 affected component
nic Foris<101.1
Event History
Jan 29, 2021
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-3346?
CVE-2021-3346 is a vulnerability in Foris before 101.1.1, as used in Turris OS, that lacks certain HTML escaping in the login template.
2
What is the severity of CVE-2021-3346?
CVE-2021-3346 has a severity rating of critical.
3
How does CVE-2021-3346 affect the software?
CVE-2021-3346 affects Foris version up to and exclusive of 101.1, as used in Nic Foris software.
4
How can CVE-2021-3346 be fixed?
To fix CVE-2021-3346, users should update Foris to version 101.1.1 or later.
5
Where can I find more information about CVE-2021-3346?
More information about CVE-2021-3346 can be found in the following references: [Link 1](https://gitlab.nic.cz/turris/foris/foris/-/blob/master/CHANGELOG.rst), [Link 2](https://gitlab.nic.cz/turris/foris/foris/-/issues/201), [Link 3](https://www.turris.com/)