CVE-2021-23648
published 2022-03-16CVE-2021-23648: The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.42%
69.9th percentile
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| braintree | sanitize-url | >= 0 < 6.0.0 | 6.0.0 |
| braintree | sanitize-url | >= unspecified < 6.0.0 | 6.0.0 |
| debian | node-mermaid | < node-mermaid 8.7.0+ds+~cs27.17.17-3+deb11u1 (bullseye) | node-mermaid 8.7.0+ds+~cs27.17.17-3+deb11u1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paypal | braintree_sanitize-url | < 6.0.0 | 6.0.0 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sanitize-url: XSS due to improper sanitization in sanitizeUrl function
vendor_redhat·2022-02-22·CVSS 5.4
CVE-2021-23648 [MEDIUM] CWE-79 sanitize-url: XSS due to improper sanitization in sanitizeUrl function
sanitize-url: XSS due to improper sanitization in sanitizeUrl function
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
A flaw was found in sanitize-url due to improper sanitization in the sanitizeUrl function. This issue causes vulnerability to Cross-site Scripting in sanitize-url.
Package: servicemesh-grafana (OpenShift Service Mesh 2.1) - Will not fix
Package: 3scale-apicast-operator-bundle-container (Red Hat 3scale API Management Platform 2) - Affected
Package: 3scale-apicast-operator-container (Red Hat 3scale API Management Platform 2) - Affected
Package: rhceph/rhceph-5-dashboard-rhel8 (Red Hat Ceph Storage 5) - Will not fix
Debian
CVE-2021-23648: node-mermaid - The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Sc...
vendor_debian·2021·CVSS 5.4
CVE-2021-23648 [MEDIUM] CVE-2021-23648: node-mermaid - The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Sc...
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
Scope: local
bullseye: resolved (fixed in 8.7.0+ds+~cs27.17.17-3+deb11u1)
GHSA
Cross-site Scripting in sanitize-url
ghsa·2022-03-17
CVE-2021-23648 [MEDIUM] CWE-79 Cross-site Scripting in sanitize-url
Cross-site Scripting in sanitize-url
The package `@braintree/sanitize-url` before 6.0.0 is vulnerable to Cross-site Scripting (XSS) due to improper sanitization in the `sanitizeUrl` function.
OSV
Cross-site Scripting in sanitize-url
osv·2022-03-17
CVE-2021-23648 [MEDIUM] Cross-site Scripting in sanitize-url
Cross-site Scripting in sanitize-url
The package `@braintree/sanitize-url` before 6.0.0 is vulnerable to Cross-site Scripting (XSS) due to improper sanitization in the `sanitizeUrl` function.
OSV
CVE-2021-23648: The package @braintree/sanitize-url before 6
osv·2022-03-16·CVSS 6.1
CVE-2021-23648 [MEDIUM] CVE-2021-23648: The package @braintree/sanitize-url before 6
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11https://github.com/braintree/sanitize-url/pull/40https://github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11https://github.com/braintree/sanitize-url/pull/40https://github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882
2022-03-16
Published