CVE-2021-23445
Cross-site Scripting (XSS)
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P
Produtos afetados
n/a · datatables.netQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://cdn.datatables.net/1.11.3/https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9bhttps://lists.debian.org/debian-lts-announce/2023/08/msg00018.htmlhttps://security.netapp.com/advisory/ntap-20240621-0006/https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544