PT-2021-15503 · Video.Js+1 · Video.Js+1

Published

2021-07-28

·

Updated

2023-08-25

·

CVE-2021-23414

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions video.js versions prior to 7.14.3
Description The issue allows bypassing HTML escaping and executing arbitrary code through the src attribute of the track tag.
Recommendations For versions prior to 7.14.3, update to version 7.14.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the track tag's src attribute to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-2012
ALT-PU-2023-2057
ALT-PU-2023-5127
CVE-2021-23414
GHSA-PP7M-6J83-M7R6
SNYK-JAVA-ORGWEBJARSBOWER-1533588
SNYK-JAVA-ORGWEBJARSNPM-1533587
SNYK-JS-VIDEOJS-1533429

Affected Products

Alt Linux
Video.Js