The vendor explicitly identifies these products as affected by this CVE.
- migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization
- mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization
- multicluster-engine/console-mce-rhel9 as a component of Multicluster Engine for Kubernetes
- workload-availability/node-healthcheck-must-gather-rhel9 as a component of Node HealthCheck Operator
- workload-availability/node-healthcheck-operator-bundle as a component of Node HealthCheck Operator
- workload-availability/node-healthcheck-rhel9-operator as a component of Node HealthCheck Operator
- openshift-lightspeed/lightspeed-agentic-console-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-console-plugin-419-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed
- openshift-service-mesh/kiali-ossmc-rhel9 as a component of OpenShift Service Mesh 3
- openshift-service-mesh/kiali-rhel9 as a component of OpenShift Service Mesh 3
- Summary
- A flaw was found in DOMPurify, a tool designed to prevent cross-site scripting (XSS) attacks by sanitizing HTML, MathML, and SVG content. When processing certain types of web page elements, DOMPurify failed to properly identify and sanitize malicious code. This oversight could allow an attacker to inject and execute harmful scripts within a user's web browser, potentially leading to information disclosure or unauthorized actions.
- Remediation
- Fix deferred
