Описание
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
An information exposure flaw was found in the sanitize-html package, when used on the backend with the style attribute allowed. This issue may allow an attacker to enumerate files in the system, including project dependencies, to gather details about the file system structure and dependencies of the targeted server.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Affected | ||
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel8 | Will not fix | ||
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | ||
| Red Hat Satellite 6 | nodejs-redhat-cloud-services-frontend-components | Affected | ||
| multicluster engine for Kubernetes 2.4 for RHEL 8 | multicluster-engine/console-mce-rhel8 | Fixed | RHBA-2024:3555 | 03.06.2024 |
| multicluster engine for Kubernetes 2.4 for RHEL 8 | multicluster-engine/multicluster-engine-console-mce-rhel8 | Fixed | RHBA-2024:3555 | 03.06.2024 |
| multicluster engine for Kubernetes 2.5 for RHEL 9 | multicluster-engine/console-mce-rhel9 | Fixed | RHBA-2024:1775 | 10.04.2024 |
| multicluster engine for Kubernetes 2.5 for RHEL 9 | multicluster-engine/multicluster-engine-console-mce-rhel9 | Fixed | RHBA-2024:1775 | 10.04.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
Versions of the package sanitize-html before 2.12.1 are vulnerable to ...
sanitize-html Information Exposure vulnerability
EPSS
5.3 Medium
CVSS3