GHSA-mm8j-9x84-m9cv
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2021-23899, https://github.com/OWASP/json-sanitizer/commit/a37f594f7378a1c76b3283e0dab9e1ab1dc0247e, https://github.com/OWASP/json-sanitizer/compare/v1.2.1...v1.2.2, https://groups.google.com/g/json-sanitizer-support/c/dAW1AeNMoA0
