A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:advanced_cluster_security:4.4::el8 | |
References |
|
Thu, 13 Feb 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Feb 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:advanced_cluster_security:4.5::el8 | |
References |
|
Mon, 10 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 10 Feb 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package. | |
Title | Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript | |
First Time appeared |
Redhat
Redhat acm Redhat advanced Cluster Security Redhat ansible Automation Platform Redhat build Keycloak Redhat cryostat Redhat discovery Redhat enterprise Linux Redhat integration Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat logging Redhat migration Toolkit Applications Redhat migration Toolkit Virtualization Redhat openshift Redhat openshift Ai Redhat openshift Data Foundation Redhat openshift Devspaces Redhat openshift Distributed Tracing Redhat openshift Lightspeed Redhat openshift Pipelines Redhat optaplanner Redhat quay Redhat red Hat 3scale Amp Redhat red Hat Single Sign On Redhat rhboac Hawtio Redhat rhdh Redhat rhel Dotnet Redhat satellite Redhat serverless Redhat service Mesh Redhat service Registry Redhat trusted Profile Analyzer |
|
Weaknesses | CWE-79 | |
CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:advanced_cluster_security:4 cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:build_keycloak: cpe:/a:redhat:cryostat:3 cpe:/a:redhat:discovery:1.0::el8 cpe:/a:redhat:integration:1 cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_enterprise_bpms_platform:7 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:logging:5 cpe:/a:redhat:migration_toolkit_applications:7 cpe:/a:redhat:migration_toolkit_virtualization:2 cpe:/a:redhat:openshift:3.11 cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift_ai cpe:/a:redhat:openshift_data_foundation:4 cpe:/a:redhat:openshift_devspaces:3: cpe:/a:redhat:openshift_distributed_tracing:3 cpe:/a:redhat:openshift_lightspeed cpe:/a:redhat:openshift_pipelines:1 cpe:/a:redhat:optaplanner:::el6 cpe:/a:redhat:quay:3 cpe:/a:redhat:red_hat_3scale_amp:2 cpe:/a:redhat:red_hat_single_sign_on:7 cpe:/a:redhat:rhboac_hawtio:4 cpe:/a:redhat:rhdh:1 cpe:/a:redhat:rhel_dotnet:6.0 cpe:/a:redhat:satellite:6 cpe:/a:redhat:serverless:1 cpe:/a:redhat:service_mesh:2 cpe:/a:redhat:service_registry:2 cpe:/a:redhat:trusted_profile_analyzer:1 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat acm Redhat advanced Cluster Security Redhat ansible Automation Platform Redhat build Keycloak Redhat cryostat Redhat discovery Redhat enterprise Linux Redhat integration Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat logging Redhat migration Toolkit Applications Redhat migration Toolkit Virtualization Redhat openshift Redhat openshift Ai Redhat openshift Data Foundation Redhat openshift Devspaces Redhat openshift Distributed Tracing Redhat openshift Lightspeed Redhat openshift Pipelines Redhat optaplanner Redhat quay Redhat red Hat 3scale Amp Redhat red Hat Single Sign On Redhat rhboac Hawtio Redhat rhdh Redhat rhel Dotnet Redhat satellite Redhat serverless Redhat service Mesh Redhat service Registry Redhat trusted Profile Analyzer |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T22:39:49.184Z
Reserved: 2024-11-26T18:56:38.187Z
Link: CVE-2024-11831

Updated: 2025-02-10T17:08:38.463Z

Status : Awaiting Analysis
Published: 2025-02-10T16:15:37.080
Modified: 2025-02-13T19:15:13.713
Link: CVE-2024-11831
