VDB
RHSA-2025%3A0329
RHSA-2025%3A0329
PUBLISHED
CVSS 8 HIGH
A flaw was found in DOMPurify that could allow for a nesting-based mXSS to not be properly sanitized.
Risk Scores
CVSS 3.1
8
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/cluster-logging-rhel9-operator@sha256:37dc87c3288fd38a4464df259ea975fdd425cd9b2a812a30344b19d25c509cac_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/cluster-logging-rhel9-operator@sha256:37dc87c3288fd38a4464df259ea975fdd425cd9b2a812a30344b19d25c509cac_amd64 |
| Red Hat | openshift-logging/vector-rhel9@sha256:d6c21081f7adfd4b9eda7af9b5a2692087e985a503b99f6093eaeb45b593ec99_ppc64le as a component of RHOL 5.8 for RHEL 9 | * |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:b3b04b4b8434fbdf85f189e12f5fa02d5ada5e8b443f2e7f27fb47d9ff3d5c77_ppc64le as a component of RHOL 5.8 for RHEL 9 | * |
| Red Hat | openshift-logging/lokistack-gateway-rhel9@sha256:e5d95fd73e0791e24d9d7fc7effbf72814a04dd215e89855168785fa9828ff9d_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/lokistack-gateway-rhel9@sha256:e5d95fd73e0791e24d9d7fc7effbf72814a04dd215e89855168785fa9828ff9d_s390x |
| Red Hat | openshift-logging/elasticsearch-rhel9-operator@sha256:4513b1f084dc5bc4aaa1157874a853347a9013c96c348218b22ff85ac907a49a_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch-rhel9-operator@sha256:4513b1f084dc5bc4aaa1157874a853347a9013c96c348218b22ff85ac907a49a_arm64 |
| Red Hat | openshift-logging/elasticsearch-rhel9-operator@sha256:dd0a1e56c1885fb82590bc63f756555fdae19279079bd9b4563007e5ddc03212_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch-rhel9-operator@sha256:dd0a1e56c1885fb82590bc63f756555fdae19279079bd9b4563007e5ddc03212_s390x |
| Red Hat | openshift-logging/logging-loki-rhel9@sha256:c26dbee6764e5466707b2ed2b89abaef5b22775f887d519c24190af2d93bc795_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-loki-rhel9@sha256:c26dbee6764e5466707b2ed2b89abaef5b22775f887d519c24190af2d93bc795_ppc64le |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:9d78894c3dde67fde95c3798a6be44250546f3615bd7c2c85c3b78c5b948e969_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:9d78894c3dde67fde95c3798a6be44250546f3615bd7c2c85c3b78c5b948e969_arm64 |
| Red Hat | openshift-logging/elasticsearch-proxy-rhel9@sha256:f54e50816a3c53e0881233c2aa1f587a5960363bf0a655547d9fc1b18b49f624_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch-proxy-rhel9@sha256:f54e50816a3c53e0881233c2aa1f587a5960363bf0a655547d9fc1b18b49f624_ppc64le |
| Red Hat | openshift-logging/vector-rhel9@sha256:b35f4a364b555214424fa0df5d607c234ec5712c480082f454c010cafe0677b4_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/vector-rhel9@sha256:b35f4a364b555214424fa0df5d607c234ec5712c480082f454c010cafe0677b4_amd64 |
| Red Hat | openshift-logging/elasticsearch6-rhel9@sha256:f804ddc928697dcfa43eadf4426efab90cad3bc53b043ffa570a6b2ec6adb78d_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch6-rhel9@sha256:f804ddc928697dcfa43eadf4426efab90cad3bc53b043ffa570a6b2ec6adb78d_s390x |
| Red Hat | openshift-logging/vector-rhel9@sha256:2b5a275b0f1b5c3f6b0d575b98f4c3850b53316882910ee74b16b68c38901308_arm64 as a component of RHOL 5.8 for RHEL 9 | * |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:9528ac4929198de9b377af2c9247373ff7768270d9a872d8dece61db2b54506f_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/fluentd-rhel9@sha256:9528ac4929198de9b377af2c9247373ff7768270d9a872d8dece61db2b54506f_amd64 |
| Red Hat | openshift-logging/lokistack-gateway-rhel9@sha256:1bd8c25b7c401341b38f7e29884340d8a9cf84a581546b8cc50ddbfe279a3e40_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/lokistack-gateway-rhel9@sha256:1bd8c25b7c401341b38f7e29884340d8a9cf84a581546b8cc50ddbfe279a3e40_arm64 |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:1d03453be061070bcb914e799ed03e536a96a2b30580f704120377dce94a8fd7_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/fluentd-rhel9@sha256:1d03453be061070bcb914e799ed03e536a96a2b30580f704120377dce94a8fd7_arm64 |
| Red Hat | openshift-logging/logging-view-plugin-rhel9@sha256:9240d5405d00377788a20ac952fd7356ee39398ec818627d8a1030e224c81bf0_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-view-plugin-rhel9@sha256:9240d5405d00377788a20ac952fd7356ee39398ec818627d8a1030e224c81bf0_ppc64le |
| Red Hat | openshift-logging/elasticsearch-rhel9-operator@sha256:a2356af786aaab3c413888a022df006442e09415433568124bf2ccb5e36875df_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch-rhel9-operator@sha256:a2356af786aaab3c413888a022df006442e09415433568124bf2ccb5e36875df_ppc64le |
| Red Hat | openshift-logging/cluster-logging-rhel9-operator@sha256:280fe34ae4c00292eeaa75b3fe72c2e0a4530fee948ea26c4eaff6591a221816_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/cluster-logging-rhel9-operator@sha256:280fe34ae4c00292eeaa75b3fe72c2e0a4530fee948ea26c4eaff6591a221816_ppc64le |
| Red Hat | openshift-logging/elasticsearch-proxy-rhel9@sha256:a86638b1509fd21548bd9dcdfd5a81c0e664b5a69cfd6622c298d4623dd91e8a_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch-proxy-rhel9@sha256:a86638b1509fd21548bd9dcdfd5a81c0e664b5a69cfd6622c298d4623dd91e8a_s390x |
| Red Hat | openshift-logging/vector-rhel9@sha256:83e1e21fc093a8edcbbf659c6233f279f2736505fb015a2bd0203c2a77ae2132_s390x as a component of RHOL 5.8 for RHEL 9 | * |
…and 39 more
Timeline
- Jan 15, 2025 CVE Published
- Apr 30, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:0329 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://issues.redhat.com/browse/LOG-6322 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0329.json advisory
- https://access.redhat.com/security/cve/CVE-2024-47875 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2318052 issue
- https://www.cve.org/CVERecord?id=CVE-2024-47875 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-47875 advisory
- https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098 advisory
- https://github.com/cure53/DOMPurify/commit/0ef5e537a514f904b6aa1d7ad9e749e365d7185f advisory
- https://github.com/cure53/DOMPurify/commit/6ea80cd8b47640c20f2f230c7920b1f4ce4fdf7a advisory
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-gx9m-whjm-85jf advisory