CVE-2021-23445Cross-site Scripting in Datatables.net

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 40.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateSep 29

Description

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

debiandebian/datatables.js< datatables.js 1.10.21+dfsg-3 (bookworm)
CVEListV5datatables/datatables.netunspecified1.11.3

Patches

🔴Vulnerability Details

3
GHSA
Cross site scripting in datatables.net2021-09-29
OSV
Cross site scripting in datatables.net2021-09-29
OSV
CVE-2021-23445: This affects the package datatables2021-09-27

📋Vendor Advisories

3
Red Hat
datatables.net: contents of array not escaped by HTML escape entities function2021-09-27
Microsoft
Cross-site Scripting (XSS)2021-09-14
Debian
CVE-2021-23445: datatables.js - This affects the package datatables.net before 1.11.3. If an array is passed to ...2021
CVE-2021-23445 — Cross-site Scripting in Datatables.net | cvebase