DOM-based cross-site scripting in DOMPurify - CVE-2024-47875

 

DOM-based cross-site scripting in DOMPurify - CVE-2024-47875

Published: October 22, 2024


Vulnerability identifier: #VU99261
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-47875
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can pass specially crafted input to the application and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

DOMPurify
Debian Linux
IBM i
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Storage Defender – Data Protect
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cloud Pak for Network Automation
QRadar Log Source Management App
IBM Cloud Pak for Security
Splunk DB Connect
Jira Service Management Server
Jira Software Data Center
Jira Service Management Data Center
IBM Business Automation Workflow
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
OpenShift Logging
IBM Sterling Connect:Direct Web Services
QRadar Suite
Jazz Reporting Service
Jira Software Server
Web Help Desk
node-dompurify (Debian package)
grafana (Red Hat package)
grafana-selinux
grafana
OpenShift Service Mesh
Red Hat OpenShift Container Platform

How to mitigate CVE-2024-47875

Install updates from vendor's website.

DOMPurify - addressed in versions 2.5.0, 3.1.3
Storage Defender – Data Protect - update to 2.0.15
QRadar Suite - update to 1.10.27.0
DB2 Data Management Console - update to 3.1.13
Splunk DB Connect - update to 4.0.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.2
Jazz Reporting Service - addressed in versions 7.0.3 iFix023, 7.1 iFix011, 7.2 iFix003
Jira Service Management Server - update to 10.3.13
Jira Software Data Center - update to 10.3.13
Jira Software Server - update to 10.3.13
Jira Service Management Data Center - update to 10.3.13
Web Help Desk - update to 12.8.4
IBM Business Automation Workflow - addressed in versions 24.0.0-IF006, 24.0.1-IF004
node-dompurify (Debian package) - update to 2.4.1+dfsg+~2.4.0-2
OpenShift Service Mesh - update to 2.5.6
Cloud Pak for Network Automation - update to 2.7.7
Red Hat OpenShift Dev Spaces - update to 3.17.0
QRadar User Behavior Analytics - update to 4.1.17
Red Hat OpenShift Container Platform - addressed in versions 4.14.41, 4.15.38, 4.16.20, 4.17.4
OpenShift Logging - addressed in versions 5.6.27, 5.8.16
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.26, 6.2.0.25, 6.3.0.11
QRadar Log Source Management App - update to 7.0.11
grafana (Red Hat package) - addressed in versions 9.2.10-19.el9_4, 9.2.10-20.el8_10, 10.2.6-7.el9_5
grafana-selinux - update to 9.2.10-20.0.1
grafana - update to 9.2.10-20.0.1

External References

Related Security Bulletins