CVE-2024-21501
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies).
Does this matter?
Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.
Description
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-538
- Affected
- apostrophecms/sanitize-html · fedoraproject/fedora
- Source
- report@snyk.io
References
- https://gist.github.com/Slonser/8b4d061abe6ee1b2e10c7242987674cfExploit, Third Party Advisory
- https://github.com/apostrophecms/apostrophe/discussions/4436Issue Tracking
- https://github.com/apostrophecms/sanitize-html/commit/c5dbdf77fe8b836d3bf4554ea39edb45281ec0b4Patch
- https://github.com/apostrophecms/sanitize-html/pull/650Patch
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EB5JPYRCTS64EA5AMV3INHDPI6I4AW7/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P4I5X6V3LYUNBMZ5YOW4BV427TH3IK4S/Mailing List
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6276557Exploit, Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-SANITIZEHTML-6256334Exploit, Third Party Advisory
- https://gist.github.com/Slonser/8b4d061abe6ee1b2e10c7242987674cfExploit, Third Party Advisory
- https://github.com/apostrophecms/apostrophe/discussions/4436Issue Tracking
- https://github.com/apostrophecms/sanitize-html/commit/c5dbdf77fe8b836d3bf4554ea39edb45281ec0b4Patch
- https://github.com/apostrophecms/sanitize-html/pull/650Patch
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EB5JPYRCTS64EA5AMV3INHDPI6I4AW7/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P4I5X6V3LYUNBMZ5YOW4BV427TH3IK4S/Mailing List
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6276557Exploit, Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-SANITIZEHTML-6256334Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.