CVE-2021-23445
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/09/2021
Last modified:
21/06/2024
Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:datatables:datatables.net:*:*:*:*:*:node.js:*:* | 1.11.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://cdn.datatables.net/1.11.3/
- https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9b
- https://lists.debian.org/debian-lts-announce/2023/08/msg00018.html
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544



