CVE-2021-32796

xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69.77%
Affected Products (NVD)
VendorProductVersion
xmldom_projectxmldom
𝑥
< 0.7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-xmldom
bookworm
0.8.6-1
fixed
bullseye
ignored
buster
ignored
sid
0.9.5-1
fixed
trixie
0.8.6-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-xmldom
bionic
dne
focal
needed
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
dne
xenial
dne