Cross-site scripting in Serialize-javascript - CVE-2024-11831
Published: January 9, 2024 / Updated: February 14, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via URL. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
watsonx.data
DataPower Operations Dashboard
watsonx Orchestrate Developer Edition
Knowledge Catalog Premium Cartridge
Storage Ceph
IBM Event Endpoint Management
IBM Cloud Pak for Security
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
QRadar Suite
Splunk Machine Learning Toolkit
thrift (Red Hat package)
ansible-collection-ansible-posix (Red Hat package)
libunwind (Red Hat package)
liborc (Red Hat package)
nvml (Red Hat package)
oath-toolkit (Red Hat package)
gperftools (Red Hat package)
lttng-ust (Red Hat package)
protobuf (Red Hat package)
ansible-collection-community-general (Red Hat package)
cephadm-ansible (Red Hat package)
libarrow (Red Hat package)
ceph (Red Hat package)
re2 (Red Hat package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage
How to mitigate CVE-2024-11831
DataPower Operations Dashboard - update to 1.0.23.3
watsonx Orchestrate Developer Edition - update to 1.15.0
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Fusion HCI - update to 2.10.0
watsonx.data - update to 2.3.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Knowledge Catalog Premium Cartridge - update to 5.2
Splunk Machine Learning Toolkit - update to 5.6.0
Storage Ceph - update to 8.1z4
IBM Event Endpoint Management - update to 11.6.0
thrift (Red Hat package) - addressed in versions 0.15.0-3.el9cp, 0.20.0-4.el10cp
ansible-collection-ansible-posix (Red Hat package) - addressed in versions 1.2.0-1.3.el9ost, 2.0.0-1.el10cp
libunwind (Red Hat package) - addressed in versions 1.6.2-2.el9cp, 1.8.0-4.el10cp
liborc (Red Hat package) - update to 2.0.3-2.el10cp
nvml (Red Hat package) - update to 2.1.0-3.el10cp
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el9cp, 2.6.12-1.el10cp
gperftools (Red Hat package) - addressed in versions 2.9.1-5.el9cp, 2.9.1-5.el10cp
lttng-ust (Red Hat package) - update to 2.13.7-5.el10cp
protobuf (Red Hat package) - update to 3.19.6-12.el10
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14, 4.17.7
ansible-collection-community-general (Red Hat package) - addressed in versions 4.0.0-1.1.el9ost, 10.7.3-1.el10cp
cephadm-ansible (Red Hat package) - addressed in versions 4.1.4-1.el9cp, 4.1.4-1.el10cp
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.8, 4.5.6
Red Hat Ceph Storage - update to 9.0
libarrow (Red Hat package) - addressed in versions 9.0.0-10.el9cp, 15.0.2-3.el10cp
App Connect Enterprise Certified Container - addressed in versions 12.0.5, 12.5.1
ceph (Red Hat package) - addressed in versions 20.1.0-144.el9cp, 20.1.0-144.el10cp
re2 (Red Hat package) - addressed in versions 20211101-4.el9cp, 20211101-4.el10cp
External References
Related Security Bulletins
- Cross-site scripting in serialize-javascript
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- IBM App Connect Enterprise Certified Container update for npm-serialize-javascript
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Multiple vulnerabilities in IBM Fusion
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Splunk Machine Learning Toolkit update for third-party components
- IBM Event Endpoint Management update for npm-serialize-javascript
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- IBM watsonx Orchestrate Developer Edition update for npm-serialize-javascript
- IBM Storage Ceph update for npm-serialize-javascript
- Multiple vulnerabilities in Red Hat Ceph Storage 9
- IBM watsonx.data update for npm-serialize-javascript
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge
- IBM DataPower Operations Dashboard update for Node.js