{"id":"GHSA-h73q-5wmj-q8pj","summary":"Cross site scripting in datatables.net ","details":"This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.","aliases":["CVE-2021-23445"],"modified":"2025-01-08T10:41:41.821442Z","published":"2021-09-29T17:11:28Z","database_specific":{"nvd_published_at":"2021-09-27T17:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-09-28T18:53:31Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23445"},{"type":"WEB","url":"https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9b"},{"type":"WEB","url":"https://cdn.datatables.net/1.11.3"},{"type":"PACKAGE","url":"https://github.com/DataTables/Dist-DataTables"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00018.html"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240621-0006"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544"}],"affected":[{"package":{"name":"datatables.net","ecosystem":"npm","purl":"pkg:npm/datatables.net"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.11.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-h73q-5wmj-q8pj/GHSA-h73q-5wmj-q8pj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}