Description
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.
Remediation
References
https://github.com/guardian/html-janitor/issues/35
https://hackerone.com/reports/308158
Related Vulnerabilities
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee10:jetty-ee10-servlets
CVE-2018-1000180 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2020-11990 Vulnerability in npm package cordova-plugin-camera
CVE-2019-16567 Vulnerability in maven package org.jenkins-ci.plugins:teamconcert