Junglewise Threat Intelligence

CVE-2024-21501: sanitize-html information exposure via style attribute

CVE-2024-21501 · Severity: low · CVSS 3.1 · Published 2024-02-24

Technologies: sanitize-html (npm). Vendors: npm.

Executive brief

sanitize-html is a widely-used Node.js library that removes potentially dangerous HTML and CSS from user-supplied content. When the style attribute is allowed and the library is used on a backend server, an attacker can craft CSS rules that leak information about the server's filesystem and installed dependencies. This allows reconnaissance of the target environment and could inform follow-up attacks.

Technical details

sanitize-html versions before 2.12.1 fail to properly sanitize CSS in the style attribute when PostCSS processes source maps. An attacker can inject CSS that uses URL references or other techniques to enumerate local files and directory structures on the backend server. The vulnerability requires that (1) the style attribute is explicitly allowed in the sanitizer configuration, and (2) the application processes user-supplied HTML on a backend server rather than in a browser. Exploitation reveals filesystem paths and dependency information without authentication. The fix in version 2.12.1 ignores source maps during PostCSS processing to prevent this leak.

Affected products

  • npm sanitize-html before 2.12.1

Timeline

  • 2024-02-24: disclosed: GHSA-rm97-x556-q36h and CVE-2024-21501 published
  • 2024-02-22: patched: Fix merged in PR #650 for version 2.12.1

References

Related threats