Deluge: Cross-Site Scripting — GLSA 202210-07

A vulnerability has been found in Deluge which could result in XSS.

Affected packages

net-p2p/deluge on all architectures
Affected versions < 2.1.1
Unaffected versions >= 2.1.1

Background

Deluge is a BitTorrent client.

Description

Deluge does not sufficiently sanitize crafted torrent file data, leading to the application interpreting untrusted data as HTML.

Impact

An attacker can achieve XSS via a crafted torrent file.

Workaround

There is no known workaround at this time.

Resolution

All Deluge users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-p2p/deluge-2.1.1"
 

References

Release date
October 16, 2022

Latest revision
October 16, 2022: 1

Severity
low

Exploitable
remote

Bugzilla entries