REDHAT-BUG-2487093: XSS
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
svelteto a version that resolves this vulnerability.Fixed in 5.55.7
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2487093?
The severity of REDHAT-BUG-2487093 is rated as high with a score of 7.
What vulnerability does REDHAT-BUG-2487093 address?
REDHAT-BUG-2487093 addresses a DOM clobbering vulnerability in Svelte that can lead to XSS attacks.
How do I fix REDHAT-BUG-2487093?
To fix REDHAT-BUG-2487093, upgrade Svelte to version 5.55.7 or later.
What does the term 'DOM clobbering' refer to in REDHAT-BUG-2487093?
In the context of REDHAT-BUG-2487093, 'DOM clobbering' refers to the overwriting of the internal state of the Svelte framework on DOM elements.
What versions of Svelte are affected by REDHAT-BUG-2487093?
Versions of Svelte prior to 5.55.7 are affected by REDHAT-BUG-2487093.