Description
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.
Remediation
References
https://github.com/guardian/html-janitor/issues/35
https://hackerone.com/reports/308158
Related Vulnerabilities
CVE-2014-0121 Vulnerability in maven package io.hawt:hawtio-karaf-terminal
CVE-2021-23797 Vulnerability in npm package http-server-node
CVE-2022-36893 Vulnerability in maven package org.jenkins-ci.plugins:rpmsign-plugin
CVE-2021-26543 Vulnerability in npm package git-parse
CVE-2017-1000392 Vulnerability in maven package org.jenkins-ci.main:jenkins-war