DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:8327 https://access.redhat.com/errata/RHSA-2024:8327
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:8678 https://access.redhat.com/errata/RHSA-2024:8678
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2024:8683 https://access.redhat.com/errata/RHSA-2024:8683
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9473 https://access.redhat.com/errata/RHSA-2024:9473
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2024:8981 https://access.redhat.com/errata/RHSA-2024:8981
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:8991 https://access.redhat.com/errata/RHSA-2024:8991
This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.5 for RHEL 8 Via RHSA-2024:9629 https://access.redhat.com/errata/RHSA-2024:9629
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:9620 https://access.redhat.com/errata/RHSA-2024:9620
This issue has been addressed in the following products: Red Hat OpenShift Dev Spaces 3 Containers Via RHSA-2024:10236 https://access.redhat.com/errata/RHSA-2024:10236