MEDIUM
sanitize-html before 1.4.3 has XSS
Published Jan 23, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.84%
Description
sanitize-html before 1.4.3 has XSS.
Affected products
No data.
- < 1.4.3
No data.
No Red Hat product state for this CVE.
sanitize-html
npm
Introduced 0 Fixed 1.4.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | sanitize-html | 0 | 1.4.3 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/advisories/GHSA-3j7m-hmh3-9jmp Advisory
- https://github.com/apostrophecms/sanitize-html/commit/762fbc7bba389f3f789cc291c1eb2b64f60f2caf
- https://github.com/apostrophecms/sanitize-html/issues/29
- https://github.com/punkave/sanitize-html/issues/29
- https://nodesecurity.io/advisories/135 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-1000237
- https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000237.json x_refsource_MISCNot Applicable
- https://www.npmjs.com/advisories/135
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 23, 2020
Updated Aug 6, 2024
Reserved Sep 20, 2016
Link CVE-2016-1000237
CISA Vulnrichment
GHSA-3J7M-HMH3-9JMP Updated n/a