cbcvebase.
CVE-2024-45801
published 2024-09-16

CVE-2024-45801: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting…

PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.84%
54.2th percentile
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected

9 ranges
VendorProductVersion rangeFixed in
atlassianjira_service_management
cure53dompurify< 2.5.42.5.4
cure53dompurify
cure53dompurify>= 0 < 2.5.02.5.0
cure53dompurify>= 0 < 2.5.42.5.4
cure53dompurify>= 3.0.0 < 3.1.33.1.3
cure53dompurify>= 3.0.0 < 3.1.33.1.3
cure53dompurify>= 3.0.1 < 3.4.03.4.0
debiannode-dompurify< node-dompurify 2.4.1+dfsg+~2.4.0-2+deb12u1 (bookworm)node-dompurify 2.4.1+dfsg+~2.4.0-2+deb12u1 (bookworm)

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian7.3HIGH
vendor_oracle7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.