Bug 2312579 (CVE-2024-11831)
Summary: | CVE-2024-11831 npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aazores, abarbaro, abhraj, abrianik, adudiak, adupliak, akostadi, alcohan, amasferr, amctagga, andrew.slice, anjoseph, anli, anpicker, anthomas, aschwart, asoldano, bbaranow, bbuckingham, bdettelb, bihu, bmaxwell, bodavis, boliveir, brian.stansberry, brking, caswilli, cbartlet, cdaley, cdewolf, chazlett, cmah, cmiranda, danken, darran.lofthouse, dbhole, dbosanac, dhanak, dholler, dkreling, dmayorov, doconnor, dosoudil, dranck, drichtar, dsimansk, dymurray, eaguilar, ebaron, ecerquei, ehelms, eric.wittmann, fdeutsch, fjuma, ggainey, ggrzybek, gkamathe, gmalinko, gparvin, gtanzill, haoli, hasun, hkataria, ibek, ibolton, istudens, ivassile, iweiss, jajackso, janstey, jcammara, jcantril, jchui, jforrest, jfula, jhe, jkang, jkoehler, jkoops, jlledo, jmatthew, jmitchel, jmontleo, jneedle, jolong, jowilson, jpallich, jprabhak, jreimann, jrokos, juwatts, jwendell, jwong, kaycoth, kegrant, kingland, koliveir, kshier, ktsao, kverlaen, lbainbri, lchilton, lgao, lphiri, mabashia, manissin, matzew, mdessi, mhulan, mjaros, mkleinhe, mkudlej, mmakovy, mnovotny, mosmerov, mposolda, mrizzi, msluiter, msochure, msvehla, mulliken, mwringe, nboldt, nipatil, njean, nmoumoul, nwallace, nyancey, omaciel, omajid, ometelka, oramraz, osousa, owatkins, pahickey, pantinor, parichar, pbraun, pcattana, pcongius, pcreech, pdelbell, pdrozd, peholase, pesilva, pgaikwad, phoracek, pierdipi, pjindal, pmackay, pskopek, psrna, ptisnovs, rcernich, rchan, rguimara, rhaigner, rhuss, rjohnson, rkubis, rmartinc, rojacob, rowaters, rstancel, rstepani, rtaniwa, saroy, sausingh, sdawley, sfeifer, sfroberg, shvarugh, simaishi, slucidi, smaestri, smallamp, smcdonal, smullick, sseago, ssilvert, stcannon, sthorger, stirabos, syedriko, tasato, teagle, tfister, thason, thavo, tjochec, tkral, tom.jenkinson, twalsh, vmuzikar, wfink, wtam, wzheng, xdharmai, yguenane |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2312824, 2312604, 2312608, 2312609, 2312610, 2312611, 2312612, 2312613, 2312614, 2312615, 2312616, 2312617, 2312618, 2312619, 2312620, 2312621, 2312622 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2024-09-16 17:03:58 UTC
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.5 Via RHSA-2025:1334 https://access.redhat.com/errata/RHSA-2025:1334 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.4 Via RHSA-2025:1468 https://access.redhat.com/errata/RHSA-2025:1468 This issue has been addressed in the following products: RHODF-4.18-RHEL-9 Via RHSA-2025:4511 https://access.redhat.com/errata/RHSA-2025:4511 This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:8479 https://access.redhat.com/errata/RHSA-2025:8479 This issue has been addressed in the following products: RHODF-4.15-RHEL-9 Via RHSA-2025:8544 https://access.redhat.com/errata/RHSA-2025:8544 This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2025:8551 https://access.redhat.com/errata/RHSA-2025:8551 |