Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Recommendation
Update the datatables.net package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.11.3
- Patched version(s): 1.11.3
References
- GHSA-h73q-5wmj-q8pj
- snyk.io
- lists.debian.org
- cdn.datatables.net
- security.netapp.com
- CVE-2021-23445
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Cross-site Scripting in epubjs - CVE-2021-33040
- DataTable Vulnerable to Cross-Site Scripting - CVE-2015-6584
- Cross-site Scripting in React Draft Wysiwyg - CVE-2021-31712
- Options structure open to Cross-site Scripting if passed unfiltered - CVE-2021-29489
You might also like:
- Tags:
- npm
- datatables.net
Anything's wrong? Let us know Last updated on June 21, 2024


