Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23445

Опубликовано: 27 сент. 2021
Источник: redhat
CVSS3: 6.1

Описание

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

An improper neutralization of input vulnerability was found in datatables.net. If an array is passed to the HTML escape entities function, it does not have its contents escaped, possibly leading to cross site scripting (XSS).

Отчет

The improper neutralization of input vulnerability in DataTables.net is considered a moderate severity issue because, while it allows for potential cross-site scripting (XSS) attacks, it requires specific conditions to be exploited effectively. An attacker must have the ability to inject malicious input into the system, and the application must pass this input to the HTML escape entities function without proper validation. Although XSS can lead to significant security risks, such as session hijacking and data theft, the impact is somewhat mitigated by the necessity of these preconditions. Moreover, this vulnerability does not compromise the underlying server or database directly, limiting its scope primarily to client-side exploitation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7datatables.netWill not fix
Red Hat Discovery 1discovery-server-containerWill not fix
Red Hat Enterprise Linux 8cockpitNot affected
Red Hat Enterprise Linux 8cockpit-appstreamNot affected
Red Hat Fuse 7datatables.netWill not fix
Red Hat JBoss Data Grid 7datatables.netWill not fix
Red Hat JBoss Enterprise Application Platform 8datatables.netNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packdatatables.netAffected
Red Hat OpenShift Container Platform 3.11openshift3/ose-consoleOut of support scope
Red Hat Process Automation 7datatables.netWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2257732datatables.net: contents of array not escaped by HTML escape entities function

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 4 лет назад

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

CVSS3: 3.1
nvd
больше 4 лет назад

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

msrc
около 1 месяца назад

Cross-site Scripting (XSS)

CVSS3: 3.1
debian
больше 4 лет назад

This affects the package datatables.net before 1.11.3. If an array is ...

CVSS3: 6.1
github
больше 4 лет назад

Cross site scripting in datatables.net

6.1 Medium

CVSS3