MEDIUM6.1
GHSA-h73q-5wmj-q8pj
Cross site scripting in datatables.net
Quick fix
GHSA-h73q-5wmj-q8pj — datatables.net: upgrade to the fixed version with the command below.
npm install datatables.net@1.11.3Details
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23445[ADVISORY]
- https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9b[WEB]
- https://cdn.datatables.net/1.11.3[WEB]
- https://github.com/DataTables/Dist-DataTables[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2023/08/msg00018.html[WEB]
- https://security.netapp.com/advisory/ntap-20240621-0006[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376[WEB]
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544[WEB]