LOW3.1
GHSA-mw6q-98mp-g8g8
Cross-site Scripting in bootstrap-table
Details
This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/bootstrap-table
Introduced in:
0No fixed version published yet for bootstrap-table (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23472[ADVISORY]
- https://github.com/wenzhixin/bootstrap-table[PACKAGE]
- https://github.com/wenzhixin/bootstrap-table/blob/develop/src/utils/index.js%23L218[WEB]
- https://security.snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1910690[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1910689[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBWENZHIXIN-1910687[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910688[WEB]
- https://snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597[WEB]