6.1
CVE-2021-23472
- EPSS 2.33%
- Veröffentlicht 03.11.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:47
- Quelle report@snyk.io
- CVE-Watchlists
- Unerledigt
Cross-site Scripting (XSS)
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bootstrap-table ≫ Bootstrap Table Version < 1.19.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.33% | 0.813 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
| report@snyk.io | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
|
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
https://github.com/wenzhixin/bootstrap-table/blob/develop/src/utils/index.js%23L218
https://security.snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1910690
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1910689
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBWENZHIXIN-1910687
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910688
https://snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597