CVE-2021-23472

NameCVE-2021-23472
DescriptionThis affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

NOT-FOR-US: bootstrap-table
URL in CVE has moved. https://github.com/wenzhixin/bootstrap-table/pull/5941

Search for package or bug name: Reporting problems