DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2024-45801

High
Low Medium High Critical
7.3
CVSS Score
Published: Sep 16, 2024
Last Modified: Sep 22, 2025

Vulnerability Description

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
L
Integrity
L
Availability
L

Known Affected Software

97 configuration(s) from 1 vendor(s)

dompurify
Version:
2.3.2
CPE:
cpe:2.3:a:cure53:dompurify:2.3.2:*:*:*:*:*:*:*
dompurify
Version:
3.1.0
CPE:
cpe:2.3:a:cure53:dompurify:3.1.0:*:*:*:*:*:*:*
dompurify
Version:
2.3.9
CPE:
cpe:2.3:a:cure53:dompurify:2.3.9:*:*:*:*:*:*:*
dompurify
Version:
2.3.1
CPE:
cpe:2.3:a:cure53:dompurify:2.3.1:*:*:*:*:*:*:*
dompurify
Version:
0.4.5
CPE:
cpe:2.3:a:cure53:dompurify:0.4.5:*:*:*:*:*:*:*
dompurify
Version:
0.6.2
CPE:
cpe:2.3:a:cure53:dompurify:0.6.2:*:*:*:*:*:*:*
dompurify
Version:
0.4.3
CPE:
cpe:2.3:a:cure53:dompurify:0.4.3:*:*:*:*:*:*:*
dompurify
Version:
0.6.6
CPE:
cpe:2.3:a:cure53:dompurify:0.6.6:*:*:*:*:*:*:*
dompurify
Version:
1.0.10
CPE:
cpe:2.3:a:cure53:dompurify:1.0.10:*:*:*:*:*:*:*
dompurify
Version:
0.7.0
CPE:
cpe:2.3:a:cure53:dompurify:0.7.0:*:*:*:*:*:*:*
dompurify
Version:
2.4.1
CPE:
cpe:2.3:a:cure53:dompurify:2.4.1:*:*:*:*:*:*:*
dompurify
Version:
2.5.1
CPE:
cpe:2.3:a:cure53:dompurify:2.5.1:*:*:*:*:*:*:*
dompurify
Version:
0.4
CPE:
cpe:2.3:a:cure53:dompurify:0.4:*:*:*:*:*:*:*
dompurify
Version:
3.1.1
CPE:
cpe:2.3:a:cure53:dompurify:3.1.1:*:*:*:*:*:*:*
dompurify
Version:
2.2.8
CPE:
cpe:2.3:a:cure53:dompurify:2.2.8:*:*:*:*:*:*:*
dompurify
Version:
0.6.0
CPE:
cpe:2.3:a:cure53:dompurify:0.6.0:*:*:*:*:*:*:*
dompurify
Version:
2.3.6
CPE:
cpe:2.3:a:cure53:dompurify:2.3.6:*:*:*:*:*:*:*
dompurify
Version:
3.0.6
CPE:
cpe:2.3:a:cure53:dompurify:3.0.6:*:*:*:*:*:*:*
dompurify
Version:
2.5.2
CPE:
cpe:2.3:a:cure53:dompurify:2.5.2:*:*:*:*:*:*:*
dompurify
Version:
0.6.5
CPE:
cpe:2.3:a:cure53:dompurify:0.6.5:*:*:*:*:*:*:*
dompurify
Version:
0.8.2
CPE:
cpe:2.3:a:cure53:dompurify:0.8.2:*:*:*:*:*:*:*
dompurify
Version:
2.2.9
CPE:
cpe:2.3:a:cure53:dompurify:2.2.9:*:*:*:*:*:*:*
dompurify
Version:
1.0.11
CPE:
cpe:2.3:a:cure53:dompurify:1.0.11:*:*:*:*:*:*:*
dompurify
Version:
3.0.2
CPE:
cpe:2.3:a:cure53:dompurify:3.0.2:*:*:*:*:*:*:*
dompurify
Version:
1.0.7
CPE:
cpe:2.3:a:cure53:dompurify:1.0.7:*:*:*:*:*:*:*
dompurify
Version:
2.4.5
CPE:
cpe:2.3:a:cure53:dompurify:2.4.5:*:*:*:*:*:*:*
dompurify
Version:
2.1.1
CPE:
cpe:2.3:a:cure53:dompurify:2.1.1:*:*:*:*:*:*:*
dompurify
Version:
2.4.0
CPE:
cpe:2.3:a:cure53:dompurify:2.4.0:*:*:*:*:*:*:*
dompurify
Version:
1.0.5
CPE:
cpe:2.3:a:cure53:dompurify:1.0.5:*:*:*:*:*:*:*
dompurify
Version:
2.5.0
CPE:
cpe:2.3:a:cure53:dompurify:2.5.0:*:*:*:*:*:*:*
dompurify
Version:
0.7.3
CPE:
cpe:2.3:a:cure53:dompurify:0.7.3:*:*:*:*:*:*:*
dompurify
Version:
2.0.17
CPE:
cpe:2.3:a:cure53:dompurify:2.0.17:*:*:*:*:*:*:*
dompurify
Version:
2.3.11
CPE:
cpe:2.3:a:cure53:dompurify:2.3.11:*:*:*:*:*:*:*
dompurify
Version:
0.6.3
CPE:
cpe:2.3:a:cure53:dompurify:0.6.3:*:*:*:*:*:*:*
dompurify
Version:
3.0.0
CPE:
cpe:2.3:a:cure53:dompurify:3.0.0:*:*:*:*:*:*:*
dompurify
Version:
2.3.5
CPE:
cpe:2.3:a:cure53:dompurify:2.3.5:*:*:*:*:*:*:*
dompurify
Version:
3.0.10
CPE:
cpe:2.3:a:cure53:dompurify:3.0.10:*:*:*:*:*:*:*
dompurify
Version:
0.7.4
CPE:
cpe:2.3:a:cure53:dompurify:0.7.4:*:*:*:*:*:*:*
dompurify
Version:
0.1
CPE:
cpe:2.3:a:cure53:dompurify:0.1:*:*:*:*:*:*:*
dompurify
Version:
0.8.9
CPE:
cpe:2.3:a:cure53:dompurify:0.8.9:*:*:*:*:*:*:*
dompurify
Version:
1.0.2
CPE:
cpe:2.3:a:cure53:dompurify:1.0.2:*:*:*:*:*:*:*
dompurify
Version:
3.0.7
CPE:
cpe:2.3:a:cure53:dompurify:3.0.7:*:*:*:*:*:*:*
dompurify
Version:
2.4.8
CPE:
cpe:2.3:a:cure53:dompurify:2.4.8:*:*:*:*:*:*:*
dompurify
Version:
0.8.7
CPE:
cpe:2.3:a:cure53:dompurify:0.8.7:*:*:*:*:*:*:*
dompurify
Version:
2.4.7
CPE:
cpe:2.3:a:cure53:dompurify:2.4.7:*:*:*:*:*:*:*
dompurify
Version:
0.8.5
CPE:
cpe:2.3:a:cure53:dompurify:0.8.5:*:*:*:*:*:*:*
dompurify
Version:
2.1.0
CPE:
cpe:2.3:a:cure53:dompurify:2.1.0:*:*:*:*:*:*:*
dompurify
Version:
0.7.1
CPE:
cpe:2.3:a:cure53:dompurify:0.7.1:*:*:*:*:*:*:*
dompurify
Version:
2.2.7
CPE:
cpe:2.3:a:cure53:dompurify:2.2.7:*:*:*:*:*:*:*
dompurify
Version:
0.8.4
CPE:
cpe:2.3:a:cure53:dompurify:0.8.4:*:*:*:*:*:*:*
dompurify
Version:
2.3.3
CPE:
cpe:2.3:a:cure53:dompurify:2.3.3:*:*:*:*:*:*:*
dompurify
Version:
2.3.0
CPE:
cpe:2.3:a:cure53:dompurify:2.3.0:*:*:*:*:*:*:*
dompurify
Version:
2.0.1
CPE:
cpe:2.3:a:cure53:dompurify:2.0.1:*:*:*:*:*:*:*
dompurify
Version:
2.3.10
CPE:
cpe:2.3:a:cure53:dompurify:2.3.10:*:*:*:*:*:*:*
dompurify
Version:
3.0.1
CPE:
cpe:2.3:a:cure53:dompurify:3.0.1:*:*:*:*:*:*:*
dompurify
Version:
0.4.2
CPE:
cpe:2.3:a:cure53:dompurify:0.4.2:*:*:*:*:*:*:*
dompurify
Version:
1.0.9
CPE:
cpe:2.3:a:cure53:dompurify:1.0.9:*:*:*:*:*:*:*
dompurify
Version:
0.8.8
CPE:
cpe:2.3:a:cure53:dompurify:0.8.8:*:*:*:*:*:*:*
dompurify
Version:
0.4.4
CPE:
cpe:2.3:a:cure53:dompurify:0.4.4:*:*:*:*:*:*:*
dompurify
Version:
2.2.2
CPE:
cpe:2.3:a:cure53:dompurify:2.2.2:*:*:*:*:*:*:*
dompurify
Version:
3.0.9
CPE:
cpe:2.3:a:cure53:dompurify:3.0.9:*:*:*:*:*:*:*
dompurify
Version:
0.8.1
CPE:
cpe:2.3:a:cure53:dompurify:0.8.1:*:*:*:*:*:*:*
dompurify
Version:
2.2.4
CPE:
cpe:2.3:a:cure53:dompurify:2.2.4:*:*:*:*:*:*:*
dompurify
Version:
2.4.9
CPE:
cpe:2.3:a:cure53:dompurify:2.4.9:*:*:*:*:*:*:*
dompurify
Version:
0.8.0
CPE:
cpe:2.3:a:cure53:dompurify:0.8.0:*:*:*:*:*:*:*
dompurify
Version:
2.4.4
CPE:
cpe:2.3:a:cure53:dompurify:2.4.4:*:*:*:*:*:*:*
dompurify
Version:
2.3.4
CPE:
cpe:2.3:a:cure53:dompurify:2.3.4:*:*:*:*:*:*:*
dompurify
Version:
2.3.12
CPE:
cpe:2.3:a:cure53:dompurify:2.3.12:*:*:*:*:*:*:*
dompurify
Version:
1.0.4
CPE:
cpe:2.3:a:cure53:dompurify:1.0.4:*:*:*:*:*:*:*
dompurify
Version:
3.0.4
CPE:
cpe:2.3:a:cure53:dompurify:3.0.4:*:*:*:*:*:*:*
dompurify
Version:
2.4.6
CPE:
cpe:2.3:a:cure53:dompurify:2.4.6:*:*:*:*:*:*:*
dompurify
Version:
2.2.3
CPE:
cpe:2.3:a:cure53:dompurify:2.2.3:*:*:*:*:*:*:*
dompurify
Version:
0.8.6
CPE:
cpe:2.3:a:cure53:dompurify:0.8.6:*:*:*:*:*:*:*
dompurify
Version:
0.3
CPE:
cpe:2.3:a:cure53:dompurify:0.3:*:*:*:*:*:*:*
dompurify
Version:
1.0.0
CPE:
cpe:2.3:a:cure53:dompurify:1.0.0:*:*:*:*:*:*:*
dompurify
Version:
3.0.11
CPE:
cpe:2.3:a:cure53:dompurify:3.0.11:*:*:*:*:*:*:*
dompurify
Version:
1.0.6
CPE:
cpe:2.3:a:cure53:dompurify:1.0.6:*:*:*:*:*:*:*
dompurify
Version:
3.0.5
CPE:
cpe:2.3:a:cure53:dompurify:3.0.5:*:*:*:*:*:*:*
dompurify
Version:
2.3.8
CPE:
cpe:2.3:a:cure53:dompurify:2.3.8:*:*:*:*:*:*:*
dompurify
Version:
2.0.2
CPE:
cpe:2.3:a:cure53:dompurify:2.0.2:*:*:*:*:*:*:*
dompurify
Version:
3.1.2
CPE:
cpe:2.3:a:cure53:dompurify:3.1.2:*:*:*:*:*:*:*
dompurify
Version:
2.4.3
CPE:
cpe:2.3:a:cure53:dompurify:2.4.3:*:*:*:*:*:*:*
dompurify
Version:
1.0.1
CPE:
cpe:2.3:a:cure53:dompurify:1.0.1:*:*:*:*:*:*:*
dompurify
Version:
0.6.7
CPE:
cpe:2.3:a:cure53:dompurify:0.6.7:*:*:*:*:*:*:*
dompurify
Version:
3.0.8
CPE:
cpe:2.3:a:cure53:dompurify:3.0.8:*:*:*:*:*:*:*
dompurify
Version:
2.0.0
CPE:
cpe:2.3:a:cure53:dompurify:2.0.0:*:*:*:*:*:*:*
dompurify
Version:
0.9.0
CPE:
cpe:2.3:a:cure53:dompurify:0.9.0:*:*:*:*:*:*:*
dompurify
Version:
0.7.2
CPE:
cpe:2.3:a:cure53:dompurify:0.7.2:*:*:*:*:*:*:*
dompurify
Version:
0.6.1
CPE:
cpe:2.3:a:cure53:dompurify:0.6.1:*:*:*:*:*:*:*
dompurify
Version:
2.2.6
CPE:
cpe:2.3:a:cure53:dompurify:2.2.6:*:*:*:*:*:*:*
dompurify
Version:
1.0.8
CPE:
cpe:2.3:a:cure53:dompurify:1.0.8:*:*:*:*:*:*:*
dompurify
Version:
0.8.3
CPE:
cpe:2.3:a:cure53:dompurify:0.8.3:*:*:*:*:*:*:*
dompurify
Version:
1.0.3
CPE:
cpe:2.3:a:cure53:dompurify:1.0.3:*:*:*:*:*:*:*
dompurify
Version:
3.0.3
CPE:
cpe:2.3:a:cure53:dompurify:3.0.3:*:*:*:*:*:*:*
dompurify
Version:
0.6.4
CPE:
cpe:2.3:a:cure53:dompurify:0.6.4:*:*:*:*:*:*:*
dompurify
Version:
2.2.0
CPE:
cpe:2.3:a:cure53:dompurify:2.2.0:*:*:*:*:*:*:*
dompurify
Version:
2.5.3
CPE:
cpe:2.3:a:cure53:dompurify:2.5.3:*:*:*:*:*:*:*
This vulnerability affects 97 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

1 patch available from vendors

View All Patches
Oracle

CPUJAN2025

Oracle Critical Patch Update Advisory - January 2025

Severity
Critical
Released
Jan 21, 2025
Restart Required
Security Update

Severity Details

7.3
out of 10.0
High

Weakness Type (CWE)

CWE-1333

Inefficient Regular Expression Complexity

Description
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Exploit Likelihood
High
Typical Severity
Medium
Abstraction Level
Base

Key Information

Published Date
September 16, 2024