VDB
RHSA-2025%3A9294
RHSA-2025%3A9294
PUBLISHED
CVSS 5.400000095367432 MEDIUM
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-resolvers-rhel8@sha256:812549c107b3917925cd951a61aab8651f6efb29efc91fe670fbba685343df8b_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | * |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-controller-rhel8@sha256:54d31d1b3a4b69e1cb82a1cc629f4fdf3676904d69f6870c97b832ae593f7f13_s390x as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-controller-rhel8@sha256:54d31d1b3a4b69e1cb82a1cc629f4fdf3676904d69f6870c97b832ae593f7f13_s390x |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-controller-rhel8@sha256:54d31d1b3a4b69e1cb82a1cc629f4fdf3676904d69f6870c97b832ae593f7f13_s390x as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-controller-rhel8@sha256:54d31d1b3a4b69e1cb82a1cc629f4fdf3676904d69f6870c97b832ae593f7f13_s390x |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-results-watcher-rhel8@sha256:0091977f0a5f7a60d74051745de700d6809e25ae91670646f2e27e99615a6b18_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | * |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-events-rhel8@sha256:28d4486ba9d8af2e73d73c4dab37736c3a0d1cc47535d5f8aa30da4101e21eff_s390x as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-events-rhel8@sha256:28d4486ba9d8af2e73d73c4dab37736c3a0d1cc47535d5f8aa30da4101e21eff_s390x |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-manual-approval-gate-webhook-rhel8@sha256:f7df3bb2a5830bb6d7f4634da2e71c9bcefcaeb3dac10d87505b48e1452327d0_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-manual-approval-gate-webhook-rhel8@sha256:f7df3bb2a5830bb6d7f4634da2e71c9bcefcaeb3dac10d87505b48e1452327d0_amd64 |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8@sha256:2ae141be6eac137dd00187bc1ac12618cb9c44cfd0984be7dfccea43c8f133c1_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8@sha256:2ae141be6eac137dd00187bc1ac12618cb9c44cfd0984be7dfccea43c8f133c1_amd64 |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8@sha256:d860644280ba29e7786d6fbb8ed47a98de34c96c1dc4e54dd13efc598b49a5f7_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | * |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-events-rhel8@sha256:7fa9bae00522781d284185af3e298825d69afd6aa8d71da865a8786bf5b3b0b7_arm64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-events-rhel8@sha256:7fa9bae00522781d284185af3e298825d69afd6aa8d71da865a8786bf5b3b0b7_arm64 |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-resolvers-rhel8@sha256:a8e02641fb831ad130cad9a8789c26bb34121ec5503666aed50b671a5de5573a_arm64 as a component of Red Hat OpenShift Pipelines 1.17 | * |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-git-init-rhel8@sha256:b46c905dbb8f06f0ed8725b8da8e59673923eaf70f93276cda3f9f542379a458_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-git-init-rhel8@sha256:b46c905dbb8f06f0ed8725b8da8e59673923eaf70f93276cda3f9f542379a458_amd64 |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:2d056d0cb096ef58a583c1abbed40dbeaec29139a5ac5309bd9082704fcde7a0_s390x as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:2d056d0cb096ef58a583c1abbed40dbeaec29139a5ac5309bd9082704fcde7a0_s390x |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-hub-ui-rhel8@sha256:a757047e35bb4d16bf57df0393a36acaa898ad1d282c02ad769a173c520d653b_arm64 as a component of Red Hat OpenShift Pipelines 1.17 | * |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8@sha256:2ae141be6eac137dd00187bc1ac12618cb9c44cfd0984be7dfccea43c8f133c1_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8@sha256:2ae141be6eac137dd00187bc1ac12618cb9c44cfd0984be7dfccea43c8f133c1_amd64 |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel8@sha256:f487357c3919655f8c1a3ef5a7eda6b503e1188f48aca0ec40d21ff3f4c0dfb3_ppc64le as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel8@sha256:f487357c3919655f8c1a3ef5a7eda6b503e1188f48aca0ec40d21ff3f4c0dfb3_ppc64le |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-sidecarlogresults-rhel8@sha256:9869a8906afe6565d7ab7657d6d63e728fa272e873b55d4148da7a19de4d26b4_amd64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-sidecarlogresults-rhel8@sha256:9869a8906afe6565d7ab7657d6d63e728fa272e873b55d4148da7a19de4d26b4_amd64 |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel8@sha256:1bbb46244380f64e3c42faf11d37d9bd266f74cde3b51943311353510fb703a1_arm64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel8@sha256:1bbb46244380f64e3c42faf11d37d9bd266f74cde3b51943311353510fb703a1_arm64 |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8@sha256:c79676ac527508f78b68f32b7c6613429c799c13cf2e38e81f88e120f8ad3c67_arm64 as a component of Red Hat OpenShift Pipelines 1.17 | * |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-nop-rhel8@sha256:fe1d9e850ccda9e01675a62851478b45ad1e4eef738a85d9915ead61f9f5d458_s390x as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-nop-rhel8@sha256:fe1d9e850ccda9e01675a62851478b45ad1e4eef738a85d9915ead61f9f5d458_s390x |
| Red Hat | registry.redhat.io/openshift-pipelines/pipelines-controller-rhel8@sha256:70f5900a3d06c2a572d2bcbf8fd6a844046532a3a50ffa4037beeeb818171073_arm64 as a component of Red Hat OpenShift Pipelines 1.17 | registry.redhat.io/openshift-pipelines/pipelines-controller-rhel8@sha256:70f5900a3d06c2a572d2bcbf8fd6a844046532a3a50ffa4037beeeb818171073_arm64 |
…and 196 more
Timeline
- Jun 19, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:9294 advisory
- https://docs.redhat.com/en/documentation/red_hat_openshift_pipelines advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://access.redhat.com/security/cve/cve-2024-21536 advisory
- https://access.redhat.com/security/cve/cve-2024-11831 advisory
- https://access.redhat.com/security/cve/cve-2024-48949 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9294.json advisory
- https://access.redhat.com/security/cve/CVE-2024-11831 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2312579 issue
- https://www.cve.org/CVERecord?id=CVE-2024-11831 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-11831 advisory
- https://github.com/yahoo/serialize-javascript/commit/f27d65d3de42affe2aac14607066c293891cec4e advisory
- https://github.com/yahoo/serialize-javascript/pull/173 advisory
- https://access.redhat.com/security/cve/CVE-2024-21536 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2319884 issue
- https://www.cve.org/CVERecord?id=CVE-2024-21536 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-21536 advisory
- https://gist.github.com/mhassan1/28be67266d82a53708ed59ce5dc3c94a advisory
- https://github.com/chimurai/http-proxy-middleware/commit/0b4274e8cc9e9a2c5a06f35fbf456ccfcebc55a5 advisory
- https://github.com/chimurai/http-proxy-middleware/commit/788b21e4aff38332d6319557d4a5b1b13b1f9a22 advisory
…and 7 more