The vendor explicitly identifies these products as affected by this CVE.
- migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization
- mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization
- multicluster-engine/console-mce-rhel9 as a component of Multicluster Engine for Kubernetes
- workload-availability/node-healthcheck-must-gather-rhel9 as a component of Node HealthCheck Operator
- workload-availability/node-healthcheck-operator-bundle as a component of Node HealthCheck Operator
- workload-availability/node-healthcheck-rhel9-operator as a component of Node HealthCheck Operator
- openshift-lightspeed/lightspeed-agentic-console-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-console-plugin-419-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed
- openshift-service-mesh/kiali-ossmc-rhel9 as a component of OpenShift Service Mesh 3
- openshift-service-mesh/kiali-rhel9 as a component of OpenShift Service Mesh 3
- Summary
- A flaw was found in DOMPurify, a library designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. A remote attacker could exploit a vulnerability in the `DOMPurify.sanitize` function when used with the `IN_PLACE: true` option. This flaw allows an attacker to bypass the sanitizer and inject malicious event-handler attributes into an attacker-controlled form element. Successful exploitation could lead to the execution of arbitrary scripts in the user's browser, potentially compromising user data or session integrity.
- Remediation
- Fix deferred
