REDHAT-BUG-2318052: XSS
Published Oct 11, 2024
·Updated
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
Affected Software
1 affected component
DOMPurify DOMPurify<2.5.0, >=3.1.3
Event History
Oct 11, 2024
Data Sourced
via Red Hat·03:20 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2318052?
The severity of REDHAT-BUG-2318052 is considered high due to the potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix REDHAT-BUG-2318052?
To fix REDHAT-BUG-2318052, upgrade DOMPurify to version 2.5.0 or later versions from 3.1.3 onwards.
3
What systems are affected by REDHAT-BUG-2318052?
Systems using versions of DOMPurify prior to 2.5.0 or between versions 2.5.0 and 3.1.3 are affected by REDHAT-BUG-2318052.
4
What type of vulnerability is REDHAT-BUG-2318052?
REDHAT-BUG-2318052 is a nesting-based mXSS vulnerability affecting the DOMPurify library.
5
Was REDHAT-BUG-2318052 successfully fixed?
Yes, REDHAT-BUG-2318052 has been successfully fixed in versions 2.5.0 and 3.1.3 of DOMPurify.