Vulnerability Description
The Refined GitHub browser extension before 21.6.8 might allow XSS via a link in a document. NOTE: github.com sends Content-Security-Policy headers to, in general, address XSS and other concerns.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Refined-Github Project | Refined-Github | < 21.6.8 |
Related Weaknesses (CWE)
References
- https://github.com/sindresorhus/refined-github/releases/tag/21.6.8Release NotesThird Party Advisory
- https://vuln.ryotak.me/advisories/47Third Party Advisory
- https://github.com/sindresorhus/refined-github/releases/tag/21.6.8Release NotesThird Party Advisory
- https://vuln.ryotak.me/advisories/47Third Party Advisory
FAQ
What is CVE-2021-34364?
CVE-2021-34364 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Refined GitHub browser extension before 21.6.8 might allow XSS via a link in a document. NOTE: github.com sends Content-Security-Policy headers to, in general, address XSS and other concerns.
How severe is CVE-2021-34364?
CVE-2021-34364 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-34364?
Check the references section above for vendor advisories and patch information. Affected products include: Refined-Github Project Refined-Github.