VDB
RHSA-2024%3A10214
RHSA-2024%3A10214
PUBLISHED
CVSS 6.099999904632568 MEDIUM
A DOM Clobbering vulnerability was found in Webpack via `AutoPublicPathRuntimeModule`. DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script through seemingly benign HTML markups in the webpage, for example, through a post or comment, and leverages the gadgets (pieces of JS code) living in the existing javascript code to transform it into executable code. This vulnerability can lead to Cross-site scripting (XSS) on websites that include Webpack-generated files and allow users to inject certain scriptless HTML tags with improperly sanitized name or ID attributes.
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Data Grid |
Timeline
- Nov 25, 2024 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:10214 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/documentation/en-us/red_hat_data_grid/8.5/html-single/red_hat_data_grid_8.5_release_notes/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2308193 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2324606 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10214.json advisory
- https://access.redhat.com/security/cve/CVE-2024-43788 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-43788 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-43788 advisory
- https://github.com/webpack/webpack/commit/955e057abc6cc83cbc3fa1e1ef67a49758bf5a61 advisory
- https://github.com/webpack/webpack/security/advisories/GHSA-4vvj-4cpr-p986 advisory
- https://research.securitum.com/xss-in-amp4email-dom-clobbering advisory
- https://scnps.co/papers/sp23_domclob.pdf advisory
- https://access.redhat.com/security/cve/CVE-2024-47072 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-47072 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-47072 advisory
- https://github.com/x-stream/xstream/commit/bb838ce2269cac47433e31c77b2b236466e9f266 advisory
- https://github.com/x-stream/xstream/security/advisories/GHSA-hfq9-hggm-c56q advisory
- https://x-stream.github.io/CVE-2024-47072.html advisory