NA

CVE-2024-21501

Published: 24/02/2024 Updated: 06/03/2024

Vulnerability Summary

Versions of the package sanitize-html prior to 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1064808 node-sanitize-html: CVE-2024-21501 Package: src:node-sanitize-html; Maintainer for src:node-sanitize-html is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 26 Feb 2024 06:03:01 UTC Severit ...