Information disclosure in sanitize-html - CVE-2024-21501

 

Information disclosure in sanitize-html - CVE-2024-21501

Published: April 17, 2024


Vulnerability identifier: #VU88801
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21501
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application when used on the backend and with the style attribute allowed. A remote attacker can enumerate files on the system, including project dependencies.


Affected software

sanitize-html
IBM Business Automation Workflow
Use Case Manager App
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
QRadar Suite
Red Hat OpenShift Container Platform
Fedora
glances
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2024-21501

Install updates from vendor's website.

sanitize-html - update to 2.12.1
Use Case Manager App - update to 3.10.0
QRadar Suite - update to 1.10.21.0
Red Hat OpenShift Container Platform - update to 4.15.9
glances - addressed in versions 4.0.5-2.fc39, 4.0.5-2.fc40
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5

External References

Related Security Bulletins