CVE-2021-20066 describes an improper local resource loading vulnerability in jsdom_project jsdom, allowing malicious web pages to manipulate local files when script execution is enabled. With a CVSS score of 5.6 (Medium), this vulnerability requires high attack complexity and has low impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:jsdom_project:jsdom:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Withdrawn Advisory: Insufficient Granularity of Access Control in JSDom
May 24, 2022jsdom: improper loading of local resources
Feb 16, 2021JSDom Improper Loading of Local Resources
Feb 16, 2021JSDom Improper Loading of Local Resources
Feb 16, 2021JSDom Improper Loading of Local Resources
Feb 16, 2021JSDom Improper Loading of Local Resources
Feb 16, 2021JSDom Improper Loading of Local Resources
Feb 16, 2021JSDom Improper Loading of Local Resources
Feb 16, 2021JSDom Improper Loading of Local Resources
Feb 16, 2021