Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
Metrics
Affected Vendors & Products
References
History
Mon, 11 Nov 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat acm
Redhat multicluster Engine |
|
CPEs | cpe:/a:redhat:acm:2.10::el9 cpe:/a:redhat:acm:2.9::el8 cpe:/a:redhat:multicluster_engine:2.4::el8 cpe:/a:redhat:multicluster_engine:2.5::el8 |
|
Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Wed, 28 Aug 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-538 |
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2024-02-24T05:00:02.731Z
Updated: 2024-08-28T17:49:19.931Z
Reserved: 2023-12-22T12:33:20.119Z
Link: CVE-2024-21501
Vulnrichment
Updated: 2024-08-01T22:20:40.904Z
NVD
Status : Awaiting Analysis
Published: 2024-02-24T05:15:44.310
Modified: 2024-08-28T18:35:07.823
Link: CVE-2024-21501
Redhat