GHSA-f4c9-cqv8-9v98
Dashboard / Vulnerabilities / GHSA-f4c9-cqv8-9v98
Summary: Withdrawn Advisory: Insufficient Granularity of Access Control in JSDom
Details: # Withdrawn Advisory This advisory has been withdrawn because the user must configure jsdom to allow access to local files. # Original Description JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious web page when script execution is enabled.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-20066, https://github.com/jsdom/jsdom/issues/3124, https://github.com/jsdom/jsdom/issues/3124#issuecomment-783502951, https://github.com/jsdom/jsdom, https://security.snyk.io/vuln/SNYK-JS-JSDOM-1075447, https://www.tenable.com/security/research/tra-2021-05
Affected packages
Package
Name: jsdom
Purl: pkg:npm/jsdom
Affected ranges
Type: SEMVER
Events:
