Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-53382

Опубликовано: 03 мар. 2025
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

A flaw was found in the prism-autoloader plugin of the Prism library. The prism-autoloader plugin uses document.currentScript as the base URL for dynamically loading other dependencies and, in certain circumstances, can be vulnerable to a DOM Clobbering attack. This issue could lead to Cross-site scripting (XSS) attacks on web pages that embed Prism and allow users to inject scriptless HTML elements, such as an img tag with a controlled name attribute.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-api-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-db-migration-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Fix deferred
OpenShift Serverlessopenshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-central-db-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel8-operatorFix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-db-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2349390prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin

EPSS

Процентиль: 22%
0.00071
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
10 месяцев назад

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
nvd
10 месяцев назад

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
debian
10 месяцев назад

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resulta ...

CVSS3: 4.9
github
10 месяцев назад

PrismJS DOM Clobbering vulnerability

EPSS

Процентиль: 22%
0.00071
Низкий

4.9 Medium

CVSS3