CVE-2024-48910

EUVD-2024-3092
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
GitHub_MCNA
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
cure53dompurify
𝑥
< 2.4.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cacti
bookworm
1.2.24+ds1-1+deb12u5
fixed
bookworm (security)
1.2.24+ds1-1+deb12u5
fixed
bullseye
vulnerable
bullseye (security)
1.2.16+ds1-2+deb11u5
fixed
forky
1.2.30+ds1-1
fixed
sid
1.2.30+ds1-1
fixed
trixie
1.2.30+ds1-1
fixed
node-dompurify
bookworm
2.4.1+dfsg+~2.4.0-2+deb12u1
fixed
bookworm (security)
vulnerable
forky
3.1.7+dfsg+~3.0.5-2
fixed
sid
3.1.7+dfsg+~3.0.5-2
fixed
trixie
3.1.7+dfsg+~3.0.5-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-dompurify
focal
dne
jammy
needs-triage
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected