Описание
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned. This issue is fixed in version 3.4.5.
A flaw was found in DOMPurify, a DOM-only cross-site scripting (XSS) sanitizer. Due to the default allowance of selectedcontent, a remote attacker could craft a malicious payload that, after initial sanitization, could be re-cloned by browsers, leading to the execution of unsanitized markup. This could result in information disclosure.
Отчет
This is a cross-site scripting (XSS) vulnerability in DOMPurify, a sanitizer for HTML, MathML, and SVG. The flaw allows a remote attacker to bypass sanitization by crafting a malicious payload that leverages the default allowance of selectedcontent. This can lead to browsers re-cloning the payload and executing unsanitized markup, resulting in information disclosure. User interaction is required for exploitation.
- AC was raised from Low to High because exploitation requires specific browser support for the experimental HTML element, which is currently only available in Chromium 148+ and WebKit 625+. Firefox and Safari are not affected, and only the single DOMPurify version 3.4.4 is vulnerable (fixed in 3.4.5), significantly narrowing the attack surface.
- Scope was lowered from Changed to Unchanged because the XSS executes within the same origin as the consuming application with no cross-domain scope change. No Red Hat product ships dompurify 3.4.4.
Меры по смягчению последствий
There is no direct mitigation for this flaw other than updating the DOMPurify library when upstream patches are available. As a defense-in-depth measure, Content Security Policy (CSP) headers that restrict inline script execution can help reduce the impact of XSS vulnerabilities. This issue is fixed in version 3.4.5.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | dompurify | Not affected | ||
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | Not affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/console-mce-rhel9 | Not affected | ||
| Node HealthCheck Operator | workload-availability/node-healthcheck-must-gather-rhel9 | Not affected | ||
| Node HealthCheck Operator | workload-availability/node-healthcheck-operator-bundle | Not affected | ||
| Node HealthCheck Operator | workload-availability/node-healthcheck-rhel9-operator | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-agentic-console-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-419-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
EPSS
5.9 Medium
CVSS3