DOM-based cross-site scripting in DOMPurify - CVE-2024-47875
Published: October 22, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can pass specially crafted input to the application and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Debian Linux
IBM i
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Storage Defender – Data Protect
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cloud Pak for Network Automation
QRadar Log Source Management App
IBM Cloud Pak for Security
Splunk DB Connect
Jira Service Management Server
Jira Software Data Center
Jira Service Management Data Center
IBM Business Automation Workflow
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
OpenShift Logging
IBM Sterling Connect:Direct Web Services
QRadar Suite
Jazz Reporting Service
Jira Software Server
Web Help Desk
node-dompurify (Debian package)
grafana (Red Hat package)
grafana-selinux
grafana
OpenShift Service Mesh
Red Hat OpenShift Container Platform
How to mitigate CVE-2024-47875
Storage Defender – Data Protect - update to 2.0.15
QRadar Suite - update to 1.10.27.0
DB2 Data Management Console - update to 3.1.13
Splunk DB Connect - update to 4.0.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.2
Jazz Reporting Service - addressed in versions 7.0.3 iFix023, 7.1 iFix011, 7.2 iFix003
Jira Service Management Server - update to 10.3.13
Jira Software Data Center - update to 10.3.13
Jira Software Server - update to 10.3.13
Jira Service Management Data Center - update to 10.3.13
Web Help Desk - update to 12.8.4
IBM Business Automation Workflow - addressed in versions 24.0.0-IF006, 24.0.1-IF004
node-dompurify (Debian package) - update to 2.4.1+dfsg+~2.4.0-2
OpenShift Service Mesh - update to 2.5.6
Cloud Pak for Network Automation - update to 2.7.7
Red Hat OpenShift Dev Spaces - update to 3.17.0
QRadar User Behavior Analytics - update to 4.1.17
Red Hat OpenShift Container Platform - addressed in versions 4.14.41, 4.15.38, 4.16.20, 4.17.4
OpenShift Logging - addressed in versions 5.6.27, 5.8.16
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.26, 6.2.0.25, 6.3.0.11
QRadar Log Source Management App - update to 7.0.11
grafana (Red Hat package) - addressed in versions 9.2.10-19.el9_4, 9.2.10-20.el8_10, 10.2.6-7.el9_5
grafana-selinux - update to 9.2.10-20.0.1
grafana - update to 9.2.10-20.0.1
External References
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-gx9m-whjm-85jf
- https://github.com/cure53/DOMPurify/commit/0ef5e537a514f904b6aa1d7ad9e749e365d7185f
- https://github.com/cure53/DOMPurify/commit/6ea80cd8b47640c20f2f230c7920b1f4ce4fdf7a
- https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098
Related Security Bulletins
- DOM-based XSS in DOMPurify
- Red Hat Enterprise Linux 8 update for grafana
- Debian update for node-dompurify
- Red Hat Enterprise Linux 9 update for grafana
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in QRadar Suite Software
- Red Hat Enterprise Linux 9 update for grafana
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- IBM Sterling Connect:Direct Web Services update for DOMPurify
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in SolarWinds Web Help Desk
- Multiple vulnerabilities in IBM QRadar Log Source Management App
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in OpenShift Logging 5.6
- Anolis OS update for grafana
- Splunk DB Connect update for third-party components
- IBM watsonx Orchestrate with watsonx Assistant Cartridge update for DOMPurify
- Splunk DB Connect update for third-party components
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Business Automation Workflow
- IBM i update for DOMPurify
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Jira Software Data Center and Server update for dompurify
- Jira Service Management Data Center and Server update for dompurify
- Multiple vulnerabilities in IBM Jazz Reporting Service