CVE-2021-23648
Summary
| CVE | CVE-2021-23648 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-16 16:15:00 UTC |
| Updated | 2023-11-07 03:30:00 UTC |
| Description | The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Application | Paypal | Braintree/sanitize-url | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cross-site Scripting (XSS) in @braintree/sanitize-url | CVE-2021-23648 | Snyk | MISC | snyk.io | |
| [SECURITY] Fedora 35 Update: grafana-7.5.15-2.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 36 Update: grafana-7.5.15-2.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 34 Update: grafana-7.5.15-2.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11 | MISC | github.com | |
| feat: decode html entities before sanitizing by crookedneighbor · Pull Request #40 · braintree/sanitize-url · GitHub | MISC | github.com | |
| [SECURITY] Fedora 36 Update: grafana-7.5.15-2.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 34 Update: grafana-7.5.15-2.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| feat: decode html entities before sanitizing by crookedneighbor · Pull Request #40 · braintree/sanitize-url · GitHub | MISC | github.com | |
| [SECURITY] Fedora 35 Update: grafana-7.5.15-2.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| sanitize-url/index.ts at main · braintree/sanitize-url · GitHub | MITRE | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Bob "Wombat" Hogg
Legacy QID Mappings
- 160238 Oracle Enterprise Linux Security Update for grafana (ELSA-2022-7519)
- 160278 Oracle Enterprise Linux Security Update for grafana (ELSA-2022-8057)
- 180818 Debian Security Update for node-mermaid (CVE-2021-23648)
- 240850 Red Hat Update for grafana security (RHSA-2022:7519)
- 240902 Red Hat Update for grafana security (RHSA-2022:8057)
- 282601 Fedora Security Update for grafana (FEDORA-2022-83405f9d5b)
- 282602 Fedora Security Update for grafana (FEDORA-2022-9dd03cab55)
- 940770 AlmaLinux Security Update for grafana (ALSA-2022:7519)
- 940826 AlmaLinux Security Update for grafana (ALSA-2022:8057)
- 960182 Rocky Linux Security Update for grafana (RLSA-2022:7519)
- 960528 Rocky Linux Security Update for grafana (RLSA-2022:8057)