REDHAT-BUG-2312631: XSS
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2312631?
The severity of REDHAT-BUG-2312631 is critical due to the potential for XSS attacks.
How do I fix REDHAT-BUG-2312631?
To fix REDHAT-BUG-2312631, update DOMPurify to a version between 2.5.4 and 3.1.3, or upgrade to a version above 3.1.3.
What types of attacks are associated with REDHAT-BUG-2312631?
REDHAT-BUG-2312631 is associated with XSS vulnerabilities and prototype pollution attacks.
Which versions of DOMPurify are affected by REDHAT-BUG-2312631?
Versions of DOMPurify that are affected by REDHAT-BUG-2312631 are those prior to 2.5.4 and versions 3.1.3 and above.
What is DOMPurify and its relevance to REDHAT-BUG-2312631?
DOMPurify is a XSS sanitizer for HTML and its recent vulnerabilities, as identified in REDHAT-BUG-2312631, allow for certain attacks to bypass its protections.