
Cloud Vulnerability DB
A community-led vulnerabilities database
Apostrophe Technologies sanitize-html before version 2.3.1 contains a security vulnerability related to improper handling of internationalized domain names (IDN). The vulnerability was discovered and disclosed on February 8, 2021, affecting the Node.js-based sanitize-html package. This vulnerability could allow attackers to bypass hostname whitelist validation that is set using the 'allowedIframeHostnames' option (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (Medium) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N. The issue specifically relates to the package's failure to properly validate internationalized domain names when checking against the allowedIframeHostnames whitelist. This could potentially allow malicious actors to bypass security controls intended to restrict iframe sources to specific trusted domains (NVD).
The vulnerability allows attackers to bypass hostname whitelist validation mechanisms, potentially enabling the injection of unauthorized iframe content from untrusted sources. This could lead to security issues such as content injection or cross-frame scripting attacks (Checkmarx Advisory).
The vulnerability is exploitable remotely without requiring authentication or user interaction. An attacker can craft specially formatted internationalized domain names to bypass the hostname validation controls (NVD).
The vulnerability was fixed in sanitize-html version 2.3.1. The fix implements the standard WHATWG URL parser to properly handle IDNA (Internationalized Domain Name) validation. Users should upgrade to version 2.3.1 or later to address this security issue (Github Changelog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."