Description
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.
Remediation
References
https://github.com/guardian/html-janitor/issues/35
https://hackerone.com/reports/308158
Related Vulnerabilities
CVE-2019-10277 Vulnerability in maven package hudson.plugins:starteam
CVE-2020-15138 Vulnerability in maven package org.webjars:prismjs
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-core
CVE-2014-3599 Vulnerability in maven package org.hornetq.rest:hornetq-rest
CVE-2016-10584 Vulnerability in npm package dalek-browser-chrome-canary