Prototype pollution in DOMPurify - CVE-2024-48910

 

Prototype pollution in DOMPurify - CVE-2024-48910

Published: October 31, 2024


Vulnerability identifier: #VU99556
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-48910
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform XSS attacks.

The vulnerability exists due to improper input validation. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.


Affected software

DOMPurify
Storage Defender – Data Protect
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Red Hat OpenShift Container Platform
Jazz Reporting Service
Web Help Desk
IBM Business Automation Workflow
Red Hat Advanced Cluster Security for Kubernetes
IBM Cloud Pak for Business Automation
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2024-48910

Install updates from vendor's website.

DOMPurify - update to 2.4.2
Storage Defender – Data Protect - update to 2.0.15
DB2 Data Management Console - update to 3.1.13
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.2
Red Hat OpenShift Container Platform - addressed in versions 4.13.62, 4.14.41, 4.17.14, 4.17.15
Jazz Reporting Service - addressed in versions 7.0.3 iFix023, 7.1 iFix011, 7.2 iFix003
Web Help Desk - update to 12.8.4
IBM Business Automation Workflow - addressed in versions 24.0.0-IF006, 24.0.1-IF004
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.5.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.18, 4.15.14, 4.16.5, 4.17.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins