CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
Percentile
69.6%
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)
DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not
correctly preserve system identifiers, FPIs or namespaces when repeatedly
parsing and serializing maliciously crafted documents. This may lead to
unexpected syntactic changes during XML processing in some downstream
applications. This is fixed in version 0.5.0. As a workaround downstream
applications can validate the input and reject the maliciously crafted
documents.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 20.04 | noarch | node-xmldom | < 0.1.27+ds-1+deb10u2build0.20.04.1 | UNKNOWN |
github.com/xmldom/xmldom/commit/d4201b9dfbf760049f457f9f08a3888d48835135
github.com/xmldom/xmldom/releases/tag/0.5.0
github.com/xmldom/xmldom/security/advisories/GHSA-h6q6-9hqw-rwfv
launchpad.net/bugs/cve/CVE-2021-21366
nvd.nist.gov/vuln/detail/CVE-2021-21366
security-tracker.debian.org/tracker/CVE-2021-21366
ubuntu.com/security/notices/USN-6102-1
www.cve.org/CVERecord?id=CVE-2021-21366
www.npmjs.com/package/xmldom
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
Percentile
69.6%