Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23648

Опубликовано: 22 фев. 2022
Источник: redhat
CVSS3: 5.4

Описание

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

A flaw was found in sanitize-url due to improper sanitization in the sanitizeUrl function. This issue causes vulnerability to Cross-site Scripting in sanitize-url.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
Red Hat 3scale API Management Platform 23scale-apicast-operator-bundle-containerAffected
Red Hat 3scale API Management Platform 23scale-apicast-operator-containerAffected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Enterprise Linux 8grafanaFixedRHSA-2022:751908.11.2022
Red Hat Enterprise Linux 9grafanaFixedRHSA-2022:805715.11.2022
Red Hat OpenShift Container Platform 4.11openshift4/ose-grafanaFixedRHSA-2022:506910.08.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2065290sanitize-url: XSS due to improper sanitization in sanitizeUrl function

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 3 лет назад

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

CVSS3: 5.4
nvd
больше 3 лет назад

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

CVSS3: 5.4
debian
больше 3 лет назад

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cro ...

CVSS3: 5.4
github
больше 3 лет назад

Cross-site Scripting in sanitize-url

rocky
больше 2 лет назад

Important: grafana security, bug fix, and enhancement update

5.4 Medium

CVSS3