CVE-2024-48910Prototype Pollution in Dompurify

Severity
9.8CRITICALNVD
CNA9.1
EPSS
2.6%
top 14.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 31

Description

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

CVEListV5cure53/dompurify< 2.4.2
NVDcure53/dompurify< 2.4.2
npmcure53/dompurify< 2.4.2
Debiancacti/cacti< 1.2.16+ds1-2+deb11u5+3

Patches

🔴Vulnerability Details

4
OSV
CVE-2024-48910: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG2024-10-31
GHSA
DOMPurify vulnerable to tampering by prototype polution2024-10-31
CVEList
DOMPurify vulnerable to tampering by prototype polution2024-10-31
OSV
DOMPurify vulnerable to tampering by prototype polution2024-10-31

📋Vendor Advisories

2
Red Hat
dompurify: DOMPurify vulnerable to tampering by prototype pollution2024-10-31
Debian
CVE-2024-48910: cacti - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM...2024

💬Community

1
Bugzilla
CVE-2024-48910 dompurify: DOMPurify vulnerable to tampering by prototype pollution2024-10-31