CVE-2021-20066: Medium severity jsdom vulnerability
Withdrawn Advisory
This advisory has been withdrawn because the user must configure jsdom to allow access to local files.
Original Description
JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious web page when script execution is enabled.
Other sources
JSDom could allow a remote attacker to bypass security restrictions, caused by improperly allowing the loading of local resources. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass access restrictions to manipulate local files by a malicious web page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20066?
CVE-2021-20066 is a vulnerability that allows the loading of local resources in JSDom, which can be exploited to manipulate local files.
What is the severity of CVE-2021-20066?
CVE-2021-20066 has a severity rating of medium (5.6).
How does CVE-2021-20066 work?
CVE-2021-20066 allows a remote attacker to bypass security restrictions in JSDom and load local resources, enabling them to manipulate local files.
What software is affected by CVE-2021-20066?
JSDom versions prior to the patched version are affected by CVE-2021-20066.
How can I mitigate CVE-2021-20066?
To mitigate CVE-2021-20066, it is recommended to update JSDom to the latest patched version.