GHSA-2589-w6xf-983r

Suggest an improvement
Source
https://github.com/advisories/GHSA-2589-w6xf-983r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-2589-w6xf-983r/GHSA-2589-w6xf-983r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2589-w6xf-983r
Aliases
  • CVE-2021-23398
Published
2021-12-10T18:58:49Z
Modified
2023-11-08T04:05:07.329507Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Cross-site scripting in react-bootstrap-table
Details

All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.

Database specific
{
    "nvd_published_at": "2021-06-24T15:15:00Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed_at": "2021-06-25T13:08:06Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / react-bootstrap-table

Package

Name
react-bootstrap-table
View open source insights on deps.dev
Purl
pkg:npm/react-bootstrap-table

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-2589-w6xf-983r/GHSA-2589-w6xf-983r.json"