Code Injection in prism - CVE-2024-53382

 

Code Injection in prism - CVE-2024-53382

Published: April 16, 2025


Vulnerability identifier: #VU107489
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-53382
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to Prism (aka PrismJS) allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.. A remote user can send a specially crafted request and execute arbitrary code on the target system.


Affected software

prism
Security QRadar EDR
watsonx Code Assistant IDE Extensions
IBM Security QRadar Log Management AQL Plugin
IBM Concert Software
IBM Observability with Instana
IBM Maximo Application Suite - Manage Component
watsonx.data
IBM Security SOAR
Red Hat Ceph Storage

How to mitigate CVE-2024-53382

Install updates from vendor's website.

prism - update to 1.30.0
IBM Security QRadar Log Management AQL Plugin - update to 1.1.3
IBM Concert Software - update to 2.0.0
watsonx.data - update to 2.2
Security QRadar EDR - update to 3.12.18
watsonx Code Assistant IDE Extensions - update to 5.2
IBM Observability with Instana - update to 1.0.293
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.24, 8.7.18, 9.0.11

External References

Related Security Bulletins