---
title: "CVE-2021-23445"
canonical: "https://kb.cynergy.app/space/MD/923730347/CVE-2021-23445"
format: markdown
---
**Description**

Certain versions of [Datatables.net](https://cve.report/software/datatables/datatables.net) from [Datatables](https://cve.report/vendor/datatables) contain the following vulnerability:

This affects the package [http://datatables.net](http://datatables.net)  before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

**Published On**

12/17/2021

**Updated On**

07/25/2022

**Trending**

FALSE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

[https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371](https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371) 

 

**Mitigation:**

![image](media://f1ce3faa-3f3c-49f3-8f9b-44ef94106283)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- [180105](https://cve.report/qid/180105) Debian Security Update for datatables.js (CVE-2021-23445)
- [980421](https://cve.report/qid/980421) Nodejs (npm) Security Update for [http://datatables.net](http://datatables.net)  (GHSA-h73q-5wmj-q8pj)

**References**

|  |  |  |
| --- | --- | --- |
| Invalid vulnerability | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| DataTables 1.11.3 | [http://cdn.datatables.net](http://cdn.datatables.net)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Cross-site Scripting (XSS) in org.webjars.bower:datatables.net | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| e835ddc5b800c47f7e9e32a91cc522f8ca7ced5c Fix: If an array was passed … · DataTables/Dist-DataTables@59a8d3f · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Cross-site Scripting (XSS) in org.webjars.npm:datatables.net | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |