REDHAT-BUG-2500695: High severity DOMPurify DOMPurify vulnerability
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify INPLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DOMPurifyto a version that resolves this vulnerability.Fixed in 3.4.7
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2500695?
The severity of REDHAT-BUG-2500695 is classified as high with a score of 7.
What does REDHAT-BUG-2500695 affect?
REDHAT-BUG-2500695 affects DOMPurify versions prior to 3.4.7.
How does REDHAT-BUG-2500695 exploit vulnerabilities?
REDHAT-BUG-2500695 allows attackers to inject malicious markup through unhandled shadow contents in template elements.
How do I fix REDHAT-BUG-2500695?
To fix REDHAT-BUG-2500695, upgrade DOMPurify to version 3.4.7 or later.
What are the risks associated with REDHAT-BUG-2500695?
The risks associated with REDHAT-BUG-2500695 include cross-site scripting (XSS) vulnerabilities due to improper sanitization.