CVE-2021-30560 is a high-severity use-after-free vulnerability in Blink XSLT within Google Chrome prior to version 91.0.4472.164, also affecting products like Debian, Splunk, and XMLSoft. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a crafted HTML page. With a CVSS score of 8.8, it presents a high risk of confidentiality, integrity, and availability compromise due to its network-based attack vector and low attack complexity. While there is no evidence of active exploitation (KEV: No) and no public exploit code available (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 91.0.4472.164CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 1.1.35CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
>= 8.2.0, < 8.2.12CPE matchmatch criteria | cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
August Third Party Package Updates in Splunk Universal Forwarder
Aug 30, 2023August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023Nokogiri has vulnerable dependencies on libxml2 and libxslt
May 24, 2022Chromium: CVE-2021-30560 Use after free in Blink XSLT
Jul 13, 2021