CVE-2021-23398
Last modified
CVE-2021-23398 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| React-Bootstrap-Table Project | React-Bootstrap-Table | All versions |
References
- https://github.com/AllenFang/react-bootstrap-table/issues/2071Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1314286Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-REACTBOOTSTRAPTABLE-1314285Exploit, Third Party Advisory
- https://github.com/AllenFang/react-bootstrap-table/issues/2071Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1314286Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-REACTBOOTSTRAPTABLE-1314285Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-23398?
How severe is CVE-2021-23398?
How do I fix CVE-2021-23398?
Are you affected by CVE-2021-23398?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
