VulnerabilityModified
CVE-2021-23445
This affects the package datatables.net before 1.11.3.
MEDIUM 6.1EPSS 1.98%
Does this matter?
Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.
Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- datatables/datatables.net
- Source
- report@snyk.io
References
- https://cdn.datatables.net/1.11.3/Release Notes, Vendor Advisory
- https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9bPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00018.html
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544Exploit, Third Party Advisory
- https://cdn.datatables.net/1.11.3/Release Notes, Vendor Advisory
- https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9bPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00018.html
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.