Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
History

Mon, 11 Nov 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat acm
Redhat multicluster Engine
CPEs cpe:/a:redhat:acm:2.10::el9
cpe:/a:redhat:acm:2.9::el8
cpe:/a:redhat:multicluster_engine:2.4::el8
cpe:/a:redhat:multicluster_engine:2.5::el8
Vendors & Products Redhat acm
Redhat multicluster Engine

Wed, 28 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-538

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2024-02-24T05:00:02.731Z

Updated: 2024-08-28T17:49:19.931Z

Reserved: 2023-12-22T12:33:20.119Z

Link: CVE-2024-21501

cve-icon Vulnrichment

Updated: 2024-08-01T22:20:40.904Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-24T05:15:44.310

Modified: 2024-08-28T18:35:07.823

Link: CVE-2024-21501

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-02-24T00:00:00Z

Links: CVE-2024-21501 - Bugzilla