Low severity3.1NVD Advisory· Published Sep 27, 2021· Updated Jun 17, 2026
CVE-2021-23445
CVE-2021-23445
Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
datatables.netnpm | < 1.11.3 | 1.11.3 |
Affected products
3- datatables.net/datatables.netdescription
Patches
Vulnerability mechanics
References
11- github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9bnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544nvdExploitThird Party AdvisoryWEB
- cdn.datatables.net/1.11.3/nvdRelease NotesVendor Advisory
- github.com/advisories/GHSA-h73q-5wmj-q8pjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23445ghsaADVISORY
- cdn.datatables.net/1.11.3ghsaWEB
- lists.debian.org/debian-lts-announce/2023/08/msg00018.htmlnvdWEB
- security.netapp.com/advisory/ntap-20240621-0006ghsaWEB
- security.netapp.com/advisory/ntap-20240621-0006/nvd
News mentions
0No linked articles in our index yet.