Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-21366
HistoryMar 12, 2021 - 12:00 a.m.

CVE-2021-21366

2021-03-1200:00:00
ubuntu.com
ubuntu.com
29
cve-2021-21366
xmldom
javascript
xml dom

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

EPSS

0.003

Percentile

69.6%

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)
DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not
correctly preserve system identifiers, FPIs or namespaces when repeatedly
parsing and serializing maliciously crafted documents. This may lead to
unexpected syntactic changes during XML processing in some downstream
applications. This is fixed in version 0.5.0. As a workaround downstream
applications can validate the input and reject the maliciously crafted
documents.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchnode-xmldom< 0.1.27+ds-1+deb10u2build0.20.04.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

EPSS

0.003

Percentile

69.6%