Reflected cross-site scripting (XSS) In cacti
Description
DOMpurify has a nesting-based mXSS DOMpurify was vulnerable to nesting-based mXSS
fixed by 0ef5e537 (2.x) and merge 943
Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking
POC is avaible under test
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1.2.26+ds1-1 | ||
debian 14 | 3.1.6+dfsg+~3.0.5-1 | ||
debian 11 | 1.2.16+ds1-2+deb11u5 | ||
debian 12 | 1.2.24+ds1-1+deb12u2 | ||
debian 12 | 2.4.1+dfsg+~2.4.0-2 | ||
debian 13 | 3.1.6+dfsg+~3.0.5-1 | ||
npm | 2.5.0, 3.1.3 | ||
rpm rhel9 | 0:10.2.6-7.el9_5 | ||
rpm rhel10 | - | - | |
rpm rhel8 | 0:9.2.10-20.el8_10 |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6.