Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 25 Apr 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora |
|
| CPEs | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora |
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apostrophecms
Apostrophecms sanitize-html |
|
| CPEs | cpe:2.3:a:apostrophecms:sanitize-html:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Apostrophecms
Apostrophecms sanitize-html |
|
| Metrics |
ssvc
|
Mon, 11 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
Redhat multicluster Engine |
|
| CPEs | cpe:/a:redhat:acm:2.10::el9 cpe:/a:redhat:acm:2.9::el8 cpe:/a:redhat:multicluster_engine:2.4::el8 cpe:/a:redhat:multicluster_engine:2.5::el8 |
|
| Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Wed, 28 Aug 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-538 |
Status: PUBLISHED
Assigner: snyk
Published: 2024-02-24T05:00:02.731Z
Updated: 2025-02-13T17:33:15.082Z
Reserved: 2023-12-22T12:33:20.119Z
Link: CVE-2024-21501
Updated: 2024-08-01T22:20:40.904Z
Status : Analyzed
Published: 2024-02-24T05:15:44.310
Modified: 2025-04-25T19:37:25.937
Link: CVE-2024-21501