Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25225

Опубликовано: 08 сент. 2025
Источник: redhat
CVSS3: 6.1

Описание

sanitize-html prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The sanitizeHtml() function in index.js does not sanitize content when using the custom transformTags option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Not affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/prometheus-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/thanos-rhel9Not affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Developer Hubrhdh/rhdh-rhel9-operatorNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-console-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2393838sanitize-html: sanitize-html cross site scripting

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 месяцев назад

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

CVSS3: 6.1
nvd
5 месяцев назад

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

CVSS3: 6.1
debian
5 месяцев назад

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-sit ...

CVSS3: 6.1
github
5 месяцев назад

sanitize-html is vulnerable to XSS through incomprehensive sanitization

6.1 Medium

CVSS3