Description
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.
Remediation
References
https://github.com/guardian/html-janitor/issues/35
https://hackerone.com/reports/308158
Related Vulnerabilities
CVE-2019-16777 Vulnerability in maven package org.webjars.bower:npm
CVE-2020-7792 Vulnerability in npm package mout
CVE-2020-6831 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-32769 Vulnerability in maven package io.micronaut:micronaut-core
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat:el-api