U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-45801

Change History

New CVE Received from GitHub, Inc. 9/16/2024 3:16:11 PM

Action Type Old Value New Value
Added Description

								
							
							
						
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Added CWE

								
							
							
						
GitHub, Inc. CWE-1333
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/cure53/DOMPurify/commit/1e520262bf4c66b5efda49e2316d6d1246ca7b21 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674 [No types assigned]