Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-11831

Опубликовано: 16 сент. 2024
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3serialize-javascriptWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
.NET 6.0 on Red Hat Enterprise Linuxrh-dotnet60-dotnetOut of support scope
OpenShift Lightspeedopenshift-lightspeed-beta/lightspeed-console-plugin-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-api-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-db-migration-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Affected
OpenShift Serverlessserialize-javascriptWill not fix
OpenShift Service Mesh 2openshift-service-mesh/kiali-ossmc-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2312579npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript

EPSS

Процентиль: 63%
0.011
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 1 года назад

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

CVSS3: 5.4
nvd
больше 1 года назад

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

msrc
12 месяцев назад

Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript

CVSS3: 5.4
debian
больше 1 года назад

A flaw was found in npm-serialize-javascript. The vulnerability occurs ...

CVSS3: 5.4
github
больше 1 года назад

Cross-site Scripting (XSS) in serialize-javascript

EPSS

Процентиль: 63%
0.011
Низкий

5.4 Medium

CVSS3