A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
History

Thu, 13 Feb 2025 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:advanced_cluster_security:4.4::el8
References

Thu, 13 Feb 2025 00:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Feb 2025 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:advanced_cluster_security:4.5::el8
References

Mon, 10 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Feb 2025 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
Title Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript
First Time appeared Redhat
Redhat acm
Redhat advanced Cluster Security
Redhat ansible Automation Platform
Redhat build Keycloak
Redhat cryostat
Redhat discovery
Redhat enterprise Linux
Redhat integration
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat logging
Redhat migration Toolkit Applications
Redhat migration Toolkit Virtualization
Redhat openshift
Redhat openshift Ai
Redhat openshift Data Foundation
Redhat openshift Devspaces
Redhat openshift Distributed Tracing
Redhat openshift Lightspeed
Redhat openshift Pipelines
Redhat optaplanner
Redhat quay
Redhat red Hat 3scale Amp
Redhat red Hat Single Sign On
Redhat rhboac Hawtio
Redhat rhdh
Redhat rhel Dotnet
Redhat satellite
Redhat serverless
Redhat service Mesh
Redhat service Registry
Redhat trusted Profile Analyzer
Weaknesses CWE-79
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:advanced_cluster_security:4
cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:cryostat:3
cpe:/a:redhat:discovery:1.0::el8
cpe:/a:redhat:integration:1
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_enterprise_bpms_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:logging:5
cpe:/a:redhat:migration_toolkit_applications:7
cpe:/a:redhat:migration_toolkit_virtualization:2
cpe:/a:redhat:openshift:3.11
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_ai
cpe:/a:redhat:openshift_data_foundation:4
cpe:/a:redhat:openshift_devspaces:3:
cpe:/a:redhat:openshift_distributed_tracing:3
cpe:/a:redhat:openshift_lightspeed
cpe:/a:redhat:openshift_pipelines:1
cpe:/a:redhat:optaplanner:::el6
cpe:/a:redhat:quay:3
cpe:/a:redhat:red_hat_3scale_amp:2
cpe:/a:redhat:red_hat_single_sign_on:7
cpe:/a:redhat:rhboac_hawtio:4
cpe:/a:redhat:rhdh:1
cpe:/a:redhat:rhel_dotnet:6.0
cpe:/a:redhat:satellite:6
cpe:/a:redhat:serverless:1
cpe:/a:redhat:service_mesh:2
cpe:/a:redhat:service_registry:2
cpe:/a:redhat:trusted_profile_analyzer:1
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat acm
Redhat advanced Cluster Security
Redhat ansible Automation Platform
Redhat build Keycloak
Redhat cryostat
Redhat discovery
Redhat enterprise Linux
Redhat integration
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat logging
Redhat migration Toolkit Applications
Redhat migration Toolkit Virtualization
Redhat openshift
Redhat openshift Ai
Redhat openshift Data Foundation
Redhat openshift Devspaces
Redhat openshift Distributed Tracing
Redhat openshift Lightspeed
Redhat openshift Pipelines
Redhat optaplanner
Redhat quay
Redhat red Hat 3scale Amp
Redhat red Hat Single Sign On
Redhat rhboac Hawtio
Redhat rhdh
Redhat rhel Dotnet
Redhat satellite
Redhat serverless
Redhat service Mesh
Redhat service Registry
Redhat trusted Profile Analyzer
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-02-13T22:39:49.184Z

Reserved: 2024-11-26T18:56:38.187Z

Link: CVE-2024-11831

cve-icon Vulnrichment

Updated: 2025-02-10T17:08:38.463Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-10T16:15:37.080

Modified: 2025-02-13T19:15:13.713

Link: CVE-2024-11831

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-09-16T00:00:00Z

Links: CVE-2024-11831 - Bugzilla