CVE Feed

    Dashboard / CVE / CVE-2024-43788

    CVE-2024-43788

    Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have discovered a DOM Clobbering vulnerability in Webpack’s `AutoPublicPathRuntimeModule`. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name` attribute) are present. Real-world exploitation of this gadget has been observed in the Canvas LMS which allows a XSS attack to happen through a javascript code compiled by Webpack (the vulnerable part is from Webpack). DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) living in the existing javascript code to transform it into executable code. This vulnerability can lead to cross-site scripting (XSS) on websites that include Webpack-generated files and allow users to inject certain scriptless HTML tags with improperly sanitized name or id attributes. This issue has been addressed in release version 5.94.0. All users are advised to upgrade. There are no known workarounds for this issue.

    Published:Aug 27, 2024
    Last Modified:Jan 9, 2025
    EPS:Aug 27, 2024
    EPSS Score:0.00179
    CVSS Score:6.4

    Affected Products

    Vendor
    Redhat
    Product
    Cryostat
    Vendor
    Redhat
    Product
    Discovery
    Vendor
    Redhat
    Product
    Jboss Data Grid
    Vendor
    Redhat
    Product
    Network Observ Optr
    Vendor
    Redhat
    Product
    Openshift Data Foundation
    Vendor
    Redhat
    Product
    Openshift Serverless
    Vendor
    Redhat
    Product
    Rhmt
    Vendor
    Redhat
    Product
    Service Mesh
    Vendor
    Webpack
    Product
    Webpack
    Vendor
    Webpack.js
    Product
    Webpack

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High