Search CVE reports
1 – 2 of 2 results
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including...
1 affected package
node-sanitize-html
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
node-sanitize-html | Needs evaluation | Needs evaluation | Not in release | Not in release |
Some fixes available 4 of 14
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
2 affected packages
jupyter-notebook, node-sanitize-html
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jupyter-notebook | Fixed | Fixed | Not affected | Not affected |
node-sanitize-html | Needs evaluation | Needs evaluation | Not in release | Not in release |