445
VMScore

CVE-2021-32796

Published: 27/07/2021 Updated: 25/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xmldom project xmldom

Vendor Advisories

Debian Bug report logs - #991612 node-xmldom: CVE-2021-32796 Package: src:node-xmldom; Maintainer for src:node-xmldom is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 28 Jul 2021 15:21:01 UTC Severity: important Tags: sec ...