Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23648

Опубликовано: 16 мар. 2022
Источник: debian

Описание

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-mermaidfixed8.14.0+~cs11.4.14-1package
node-mermaidfixed8.7.0+ds+~cs27.17.17-3+deb11u1bullseyepackage

Примечания

  • https://github.com/braintree/sanitize-url/pull/40

  • src:node-mermaid provides embedded @braintree/sanitize-url

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 3 лет назад

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

CVSS3: 5.4
redhat
больше 3 лет назад

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

CVSS3: 5.4
nvd
больше 3 лет назад

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

CVSS3: 5.4
github
больше 3 лет назад

Cross-site Scripting in sanitize-url

rocky
больше 2 лет назад

Important: grafana security, bug fix, and enhancement update