---
title: "CVE-2021-23414"
canonical: "https://kb.cynergy.app/space/MD/923632255/CVE-2021-23414"
format: markdown
---
**Description**

This affects the package video.js before 7.14.3. The src attribute of track tag allows bypassing HTML escaping and executing arbitrary code.  


**Published On**

12/17/2021

**Updated On**

07/25/2022

**Trending**

FALSE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

[https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1533588](https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1533588) 

 

**Mitigation:**

![image](media://8a40bb83-0697-4d7d-aaef-04cdcf0e6639)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- [981381](https://cve.report/qid/981381) Nodejs (npm) Security Update for video.js (GHSA-pp7m-6j83-m7r6)

**References**

![image](media://eabebcc4-f318-495d-ad8c-54087d4d6cd4)

|  |  |  |
| --- | --- | --- |
| Cross-site Scripting (XSS) in video.js | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Cross-site Scripting (XSS) in org.webjars.bower:video.js | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| fix: remove IE8 url parsing workaround (#7334) · videojs/video.js@b3acf66 · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Cross-site Scripting (XSS) in org.webjars.npm:video.js | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |