Prototype pollution in node-gettext - CVE-2024-21528
Published: February 17, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation within the addTranslations() function in gettext.js. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
SUSE Manager Proxy 5.0
SUSE Manager Retail Branch Server 5.0
SUSE Manager Server 5.0
SUSE Linux Enterprise Micro
OpenShift Data Foundation (formerly OpenShift Container Storage)
suse-manager-5.0-s390x-server-hub-xmlrpc-api-image
suse-manager-5.0-ppc64le-server-hub-xmlrpc-api-image
suse-manager-5.0-aarch64-server-hub-xmlrpc-api-image
suse-manager-5.0-x86_64-server-hub-xmlrpc-api-image
suse-manager-5.0-s390x-server-attestation-image
suse-manager-5.0-ppc64le-server-attestation-image
suse-manager-5.0-aarch64-server-attestation-image
suse-manager-5.0-x86_64-server-attestation-image
suse-manager-5.0-aarch64-proxy-tftpd-image
suse-manager-5.0-x86_64-proxy-ssh-image
suse-manager-5.0-x86_64-proxy-tftpd-image
suse-manager-5.0-x86_64-proxy-squid-image
suse-manager-5.0-ppc64le-proxy-ssh-image
suse-manager-5.0-aarch64-proxy-ssh-image
suse-manager-5.0-aarch64-proxy-squid-image
suse-manager-5.0-ppc64le-proxy-squid-image
suse-manager-5.0-ppc64le-proxy-tftpd-image
suse-manager-5.0-s390x-proxy-ssh-image
suse-manager-5.0-s390x-proxy-squid-image
suse-manager-5.0-s390x-proxy-tftpd-image
suse-manager-5.0-x86_64-server-migration-14-16-image
suse-manager-5.0-s390x-server-migration-14-16-image
suse-manager-5.0-ppc64le-server-migration-14-16-image
suse-manager-5.0-aarch64-server-migration-14-16-image
suse-manager-5.0-ppc64le-proxy-httpd-image
suse-manager-5.0-x86_64-proxy-httpd-image
suse-manager-5.0-aarch64-proxy-httpd-image
suse-manager-5.0-s390x-proxy-httpd-image
suse-manager-5.0-s390x-proxy-salt-broker-image
suse-manager-5.0-aarch64-proxy-salt-broker-image
suse-manager-5.0-ppc64le-proxy-salt-broker-image
suse-manager-5.0-x86_64-proxy-salt-broker-image
suse-manager-5.0-x86_64-server-image
suse-manager-5.0-ppc64le-server-image
suse-manager-5.0-aarch64-server-image
suse-manager-5.0-s390x-server-image
How to mitigate CVE-2024-21528
suse-manager-5.0-s390x-server-hub-xmlrpc-api-image - update to 5.0.3-6.9.5
suse-manager-5.0-ppc64le-server-hub-xmlrpc-api-image - update to 5.0.3-6.9.5
suse-manager-5.0-aarch64-server-hub-xmlrpc-api-image - update to 5.0.3-6.9.5
suse-manager-5.0-x86_64-server-hub-xmlrpc-api-image - update to 5.0.3-6.9.5
suse-manager-5.0-s390x-server-attestation-image - update to 5.0.3-6.9.10
suse-manager-5.0-ppc64le-server-attestation-image - update to 5.0.3-6.9.10
suse-manager-5.0-aarch64-server-attestation-image - update to 5.0.3-6.9.10
suse-manager-5.0-x86_64-server-attestation-image - update to 5.0.3-6.9.10
suse-manager-5.0-aarch64-proxy-tftpd-image - update to 5.0.3-7.9.6
suse-manager-5.0-x86_64-proxy-ssh-image - update to 5.0.3-7.9.6
suse-manager-5.0-x86_64-proxy-tftpd-image - update to 5.0.3-7.9.6
suse-manager-5.0-x86_64-proxy-squid-image - update to 5.0.3-7.9.6
suse-manager-5.0-ppc64le-proxy-ssh-image - update to 5.0.3-7.9.6
suse-manager-5.0-aarch64-proxy-ssh-image - update to 5.0.3-7.9.6
suse-manager-5.0-aarch64-proxy-squid-image - update to 5.0.3-7.9.6
suse-manager-5.0-ppc64le-proxy-squid-image - update to 5.0.3-7.9.6
suse-manager-5.0-ppc64le-proxy-tftpd-image - update to 5.0.3-7.9.6
suse-manager-5.0-s390x-proxy-ssh-image - update to 5.0.3-7.9.6
suse-manager-5.0-s390x-proxy-squid-image - update to 5.0.3-7.9.6
suse-manager-5.0-s390x-proxy-tftpd-image - update to 5.0.3-7.9.6
suse-manager-5.0-x86_64-server-migration-14-16-image - update to 5.0.3-7.9.7
suse-manager-5.0-s390x-server-migration-14-16-image - update to 5.0.3-7.9.7
suse-manager-5.0-ppc64le-server-migration-14-16-image - update to 5.0.3-7.9.7
suse-manager-5.0-aarch64-server-migration-14-16-image - update to 5.0.3-7.9.7
suse-manager-5.0-ppc64le-proxy-httpd-image - update to 5.0.3-7.9.12
suse-manager-5.0-x86_64-proxy-httpd-image - update to 5.0.3-7.9.12
suse-manager-5.0-aarch64-proxy-httpd-image - update to 5.0.3-7.9.12
suse-manager-5.0-s390x-proxy-httpd-image - update to 5.0.3-7.9.12
suse-manager-5.0-s390x-proxy-salt-broker-image - update to 5.0.3-7.9.14
suse-manager-5.0-aarch64-proxy-salt-broker-image - update to 5.0.3-7.9.14
suse-manager-5.0-ppc64le-proxy-salt-broker-image - update to 5.0.3-7.9.14
suse-manager-5.0-x86_64-proxy-salt-broker-image - update to 5.0.3-7.9.14
suse-manager-5.0-x86_64-server-image - update to 5.0.3-7.11.12
suse-manager-5.0-ppc64le-server-image - update to 5.0.3-7.11.12
suse-manager-5.0-aarch64-server-image - update to 5.0.3-7.11.12
suse-manager-5.0-s390x-server-image - update to 5.0.3-7.11.12
External References
Related Security Bulletins
- Prototype pollution in node-gettext
- SUSE update for Maintenance update for SUSE Manager 5.0: Server, Proxy and Retail Branch Server
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18