ELA-920-1 datatables.js security update

Cross-site Scripting (XSS) vulnerability

2023-08-15
Packagedatatables.js
Version1.10.13+dfsg-2+deb9u1 (stretch)
Related CVEs CVE-2021-23445


datatables.js is a jQuery plug-in that makes nice tables from different data sources.

It was discovered that if an array is passed to the HTML escape entities function, it would not have its contents escaped.



For Debian 9 stretch, these problems have been fixed in version 1.10.13+dfsg-2+deb9u1.

We recommend that you upgrade your datatables.js packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.