Beveiligingsadvies

CVE-2021-23784

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-11-03 17:20:42
Laatst bijgewerkt 2024-09-17 01:45:32
Toegewezen door snyk
CVSS-score 5.4
Status PUBLISHED

Beschrijving

This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.