CVE-2021-23784

MEDIUM

Tempura < 0.4.0 - XSS

Title source: rule
STIX 2.1

Description

This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.

References (3)

Core 3
Core References
Exploit, Mitigation, Patch, Third Party Advisory, VDB Entry x_refsource_misc
https://snyk.io/vuln/SNYK-JS-TEMPURA-1569633
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/lukeed/tempura/releases/tag/v0.4.0

Scores

CVSS v3 5.4
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
npm/tempura 0 - 0.4.0npm
tempura_project/tempura < 0.4.0
Published Nov 03, 2021
Tracked Since Feb 18, 2026