CVE-2021-32796

xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
GitHub_MCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
xmldom_projectxmldom
𝑥
< 0.7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-xmldom
bullseye
ignored
buster
ignored
trixie
0.8.6-1
fixed
bookworm
0.8.6-1
fixed
sid
0.9.5-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-xmldom
noble
needs-triage
mantic
ignored
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
ignored
hirsute
ignored
focal
needed
bionic
dne
xenial
ignored
trusty
dne