CVE-2021-3377
nodejs-ansi_up: XSS due to insufficient URL sanitization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.
El paquete npm ansi_up convierte los códigos de escape ANSI en HTML. En ansi_up versión v4, los códigos de escape ANSI pueden ser usados para crear hipervínculos HTML. Debido a un saneamiento insuficiente de la URL, esta funcionalidad está afectada por una vulnerabilidad de tipo cross-site scripting (XSS). Este problema es corregido en versión v5.0.0
A flaw was found in npm package ansi_up versions < 5.0.0 when parsing untrusted user input. An attacker could take advantage of this by introducing ANSI escape codes to inject arbitrary HTML and JavaScript in result mounting a cross-site scripting (XSS) attack.
Red Hat Advanced Cluster Management for Kubernetes 2.3.0 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix several bugs and security issues. Issues addressed include code execution, cross site scripting, denial of service, integer overflow, and null pointer vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-01 CVE Reserved
- 2021-03-05 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://doyensec.com/resources/Doyensec_Advisory_ansi_up4_XSS.pdf | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/drudru/ansi_up/commit/c8c726ed1db979bae4f257b7fa41775155ba2e27 | 2021-03-09 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-3377 | 2021-08-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1936427 | 2021-08-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ansi Up Project Search vendor "Ansi Up Project" | Ansi Up Search vendor "Ansi Up Project" for product "Ansi Up" | < 5.0.0 Search vendor "Ansi Up Project" for product "Ansi Up" and version " < 5.0.0" | node.js |
Affected
|