GHSA-fx46-whrj-73v5
Dashboard / Vulnerabilities / GHSA-fx46-whrj-73v5
Summary: Bypassing Sanitization using DOM clobbering in html-janitor
Details: All versions of `html-janitor` are vulnerable to cross-site scripting (XSS). Arbitrary HTML can pass the sanitization process, which can be unexpected and dangerous (XSS) in case user-controlled input is passed to the clean function." ## Recommendation Upgrade to version 2.0.4 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-0928, https://github.com/guardian/html-janitor/issues/35, https://hackerone.com/reports/308158, https://github.com/advisories/GHSA-fx46-whrj-73v5, https://www.npmjs.com/advisories/569
Affected packages
Package
Name: html-janitor
Purl: pkg:npm/html-janitor
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
