Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
History

Wed, 28 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-538

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2024-02-24T05:00:02.731Z

Updated: 2024-08-28T17:49:19.931Z

Reserved: 2023-12-22T12:33:20.119Z

Link: CVE-2024-21501

cve-icon Vulnrichment

Updated: 2024-08-01T22:20:40.904Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-24T05:15:44.310

Modified: 2024-08-28T18:35:07.823

Link: CVE-2024-21501

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-02-24T00:00:00Z

Links: CVE-2024-21501 - Bugzilla