CVE-2021-32796
As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
Does this matter?
Lower severity and a low EPSS score (1.36%). Track it; it rarely justifies an emergency change on its own.
Description
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.36% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-116, CWE-91
- Affected
- xmldom project/xmldom
- Source
- security-advisories@github.com
References
- https://github.com/xmldom/xmldom/commit/7b4b743917a892d407356e055b296dcd6d107e8bPatch, Third Party Advisory
- https://github.com/xmldom/xmldom/security/advisories/GHSA-5fg8-2547-mr8qThird Party Advisory
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/Not Applicable, Third Party Advisory
- https://github.com/xmldom/xmldom/commit/7b4b743917a892d407356e055b296dcd6d107e8bPatch, Third Party Advisory
- https://github.com/xmldom/xmldom/security/advisories/GHSA-5fg8-2547-mr8qThird Party Advisory
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/Not Applicable, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.