Junglewise Threat Intelligence

CVE-2021-23784: tempura cross-site scripting in esc function

CVE-2021-23784 · Severity: low · CVSS 3.1 · Published 2021-11-08

Vendors: npm.

Executive brief

tempura is a JavaScript template library used to render dynamic content in web applications. A flaw in its escape function allows attackers to inject malicious scripts by passing arrays as input, which bypass HTML sanitization and execute in users' browsers. This can lead to session theft, credential harvesting, or defacement of web pages served by applications using this library.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in tempura's esc function (CWE-79). When the input to esc is of type object (specifically an array), the function returns the input unsanitized instead of escaping HTML special characters. The attack is network-accessible and requires no authentication but does require user interaction (e.g., clicking a link or viewing a crafted page). An attacker can exploit this to inject arbitrary JavaScript that executes in the context of a vulnerable application. The issue was fixed in version 0.4.0, which ensures esc always returns a properly escaped string.

Affected products

  • lukeed tempura before 0.4.0

Timeline

  • 2021-11-08: disclosed
  • 2021-11-04: patched: fix commit available

References