Related Vulnerabilities: CVE-2021-23648  

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

Description

The MITRE CVE dictionary describes this issue as:

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

Additional Information

  • Bugzilla 2065290: CVE-2021-23648 sanitize-url: XSS
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • FAQ: Frequently asked questions about CVE-2021-23648