CVE | CVE-2023-27592 |
CVE Title | |
Published Date | 2023-03-17T20:15Z |
Modified Date | 2023-03-20T02:46Z |
CWE Type | CWE-79 |
Description | Miniflux is a feed reader. Since v2.0.25, Miniflux will automatically proxy images served over HTTP to prevent mixed content errors. When an outbound request made by the Go HTTP client fails, the `html.ServerError` is returned unescaped without the expected Content Security Policy header added to valid responses. By creating an RSS feed item with the inline description containing an ` |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://github.com/miniflux/v2/releases/tag/2.0.43 |
Reference Description | MISC https://github.com/miniflux/v2/releases/tag/2.0.43 |
Reference URL | https://github.com/miniflux/v2/releases/tag/2.0.25 |
Reference Description | MISC https://github.com/miniflux/v2/releases/tag/2.0.25 |
Reference URL | https://github.com/miniflux/v2/blob/b2fd84e0d376a3af6329b9bb2e772ce38a25c31c/ui/proxy.go#L76 |
Reference Description | MISC https://github.com/miniflux/v2/blob/b2fd84e0d376a3af6329b9bb2e772ce38a25c31c/ui/proxy.go#L76 |
Reference URL | https://github.com/miniflux/v2/pull/1746 |
Reference Description | MISC https://github.com/miniflux/v2/pull/1746 |
Reference URL | https://miniflux.app/docs/configuration.html#proxy-images |
Reference Description | MISC https://miniflux.app/docs/configuration.html#proxy-images |
Sources | NIST MITRE |
Note
- No CVSS data for this CVE