First published: Mon Oct 07 2024(Updated: )
An update is now available for the Red Hat build of Cryostat 3 on RHEL 8.<br>Security Fix(es):<br><li> webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788)</li> <li> dompurify: XSS vulnerability via prototype pollution (CVE-2024-45801)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Cryostat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2024:7706 addresses a DOM Clobbering vulnerability in webpack (CVE-2024-43788) and an XSS vulnerability via prototype pollution in dompurify (CVE-2024-45801).
The vulnerabilities can potentially allow unauthorized access and execution of malicious scripts, compromising the integrity and security of your Red Hat Cryostat installation.
To fix the vulnerabilities in RHSA-2024:7706, update your Red Hat Cryostat installation to the latest version provided in the advisory.
Yes, it is recommended to apply the update for RHSA-2024:7706 immediately to mitigate potential security risks associated with the vulnerabilities.
You can find more information about RHSA-2024:7706 in the official Red Hat advisory and related bug reports.