CVE-2021-32796
published 2021-07-27CVE-2021-32796: xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.35%
68.2th percentile
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-xmldom | < node-xmldom 0.7.3-1 (bookworm) | node-xmldom 0.7.3-1 (bookworm) |
| xmldom | xmldom | < 0.7.0 | 0.7.0 |
| xmldom | xmldom | >= 0 < 0.7.0 | 0.7.0 |
| xmldom | xmldom | 0 – 0.6.0 | — |
| xmldom_project | xmldom | < 0.7.0 | 0.7.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Misinterpretation of malicious XML input
osv·2021-08-03
CVE-2021-32796 [MEDIUM] Misinterpretation of malicious XML input
Misinterpretation of malicious XML input
### Impact
xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications.
### Patches
Update to one of the fixed versions of `@xmldom/xmldom` (`>=0.7.0`)
See issue #271 for the status of publishing `xmldom` to npm or join #270 for Q&A/discussion until it's resolved.
### Workarounds
Downstream applications can validate the input and reject the maliciously crafted documents.
### References
Similar to this one reported on the Go standard library:
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/
- https://mattermost.com/blog/securing-xml-implementations
GHSA
Misinterpretation of malicious XML input
ghsa·2021-08-03
CVE-2021-32796 [MEDIUM] CWE-116 Misinterpretation of malicious XML input
Misinterpretation of malicious XML input
### Impact
xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications.
### Patches
Update to one of the fixed versions of `@xmldom/xmldom` (`>=0.7.0`)
See issue #271 for the status of publishing `xmldom` to npm or join #270 for Q&A/discussion until it's resolved.
### Workarounds
Downstream applications can validate the input and reject the maliciously crafted documents.
### References
Similar to this one reported on the Go standard library:
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/
- https://mattermost.com/blog/securing-xml-implementations
OSV
CVE-2021-32796: xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module
osv·2021-07-27·CVSS 5.3
CVE-2021-32796 [MEDIUM] CVE-2021-32796: xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
Red Hat
nodejs-xmldom: misinterpretation of malicious XML input
vendor_redhat·2021-07-27·CVSS 6.5
CVE-2021-32796 [MEDIUM] CWE-20 nodejs-xmldom: misinterpretation of malicious XML input
nodejs-xmldom: misinterpretation of malicious XML input
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
A flaw was found in nodejs-xmldom. The xmldom library is an open-source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Xmldom does not correctly escape special characters when serializing e
Debian
CVE-2021-32796: node-xmldom - xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Cor...
vendor_debian·2021·CVSS 6.5
CVE-2021-32796 [MEDIUM] CVE-2021-32796: node-xmldom - xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Cor...
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
Scope: local
bookworm: resolved (fixed in 0.7.3-1)
bullseye: open
forky: resolved (fixed in 0.7.3-1)
sid: resolved (fixed in 0.7.3-1)
trixie: resolved (fixed in 0.7.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/xmldom/xmldom/commit/7b4b743917a892d407356e055b296dcd6d107e8bhttps://github.com/xmldom/xmldom/security/advisories/GHSA-5fg8-2547-mr8qhttps://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/https://github.com/xmldom/xmldom/commit/7b4b743917a892d407356e055b296dcd6d107e8bhttps://github.com/xmldom/xmldom/security/advisories/GHSA-5fg8-2547-mr8qhttps://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/
2021-07-27
Published