CVE-2024-21501

EUVD-2024-0719
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
snykCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
apostrophecmssanitize-html
𝑥
< 2.12.1
apostrophecmssanitize-html
𝑥
< 2.12.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-sanitize-html
bookworm
no-dsa
forky
2.14.0+~2.13.0-1
fixed
sid
2.14.0+~2.13.0-1
fixed
trixie
2.14.0+~2.13.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-sanitize-html
bionic
dne
focal
dne
jammy
needs-triage
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
trusty
dne
xenial
dne