Cross-site scripting in Serialize-javascript - CVE-2024-11831

 

Cross-site scripting in Serialize-javascript - CVE-2024-11831

Published: January 9, 2024 / Updated: February 14, 2025


Vulnerability identifier: #VU85240
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-11831
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data passed via URL. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Serialize-javascript
watsonx.data
DataPower Operations Dashboard
watsonx Orchestrate Developer Edition
Knowledge Catalog Premium Cartridge
Storage Ceph
IBM Event Endpoint Management
IBM Cloud Pak for Security
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
QRadar Suite
Splunk Machine Learning Toolkit
thrift (Red Hat package)
ansible-collection-ansible-posix (Red Hat package)
libunwind (Red Hat package)
liborc (Red Hat package)
nvml (Red Hat package)
oath-toolkit (Red Hat package)
gperftools (Red Hat package)
lttng-ust (Red Hat package)
protobuf (Red Hat package)
ansible-collection-community-general (Red Hat package)
cephadm-ansible (Red Hat package)
libarrow (Red Hat package)
ceph (Red Hat package)
re2 (Red Hat package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage

How to mitigate CVE-2024-11831

Install updates from vendor's website.

Serialize-javascript - update to 6.0.2
DataPower Operations Dashboard - update to 1.0.23.3
watsonx Orchestrate Developer Edition - update to 1.15.0
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Fusion HCI - update to 2.10.0
watsonx.data - update to 2.3.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Knowledge Catalog Premium Cartridge - update to 5.2
Splunk Machine Learning Toolkit - update to 5.6.0
Storage Ceph - update to 8.1z4
IBM Event Endpoint Management - update to 11.6.0
thrift (Red Hat package) - addressed in versions 0.15.0-3.el9cp, 0.20.0-4.el10cp
ansible-collection-ansible-posix (Red Hat package) - addressed in versions 1.2.0-1.3.el9ost, 2.0.0-1.el10cp
libunwind (Red Hat package) - addressed in versions 1.6.2-2.el9cp, 1.8.0-4.el10cp
liborc (Red Hat package) - update to 2.0.3-2.el10cp
nvml (Red Hat package) - update to 2.1.0-3.el10cp
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el9cp, 2.6.12-1.el10cp
gperftools (Red Hat package) - addressed in versions 2.9.1-5.el9cp, 2.9.1-5.el10cp
lttng-ust (Red Hat package) - update to 2.13.7-5.el10cp
protobuf (Red Hat package) - update to 3.19.6-12.el10
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14, 4.17.7
ansible-collection-community-general (Red Hat package) - addressed in versions 4.0.0-1.1.el9ost, 10.7.3-1.el10cp
cephadm-ansible (Red Hat package) - addressed in versions 4.1.4-1.el9cp, 4.1.4-1.el10cp
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.8, 4.5.6
Red Hat Ceph Storage - update to 9.0
libarrow (Red Hat package) - addressed in versions 9.0.0-10.el9cp, 15.0.2-3.el10cp
App Connect Enterprise Certified Container - addressed in versions 12.0.5, 12.5.1
ceph (Red Hat package) - addressed in versions 20.1.0-144.el9cp, 20.1.0-144.el10cp
re2 (Red Hat package) - addressed in versions 20211101-4.el9cp, 20211101-4.el10cp

External References

Related Security Bulletins