CVE-2024-53382

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-53382
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53382.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-53382
Aliases
Related
Published
2025-03-03T07:15:33Z
Modified
2025-03-03T22:49:10.101289Z
Summary
[none]
Details

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

References

Affected packages

Debian:11 / node-prismjs

Package

Name
node-prismjs
Purl
pkg:deb/debian/node-prismjs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.23.0+dfsg-1
1.23.0+dfsg-1+deb11u1
1.23.0+dfsg-1+deb11u2
1.25.0+dfsg-1
1.27.0+dfsg+~1.26.0-1
1.28.0+dfsg+~1.26.0-1
1.29.0+dfsg+~1.26.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / node-prismjs

Package

Name
node-prismjs
Purl
pkg:deb/debian/node-prismjs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.29.0+dfsg+~1.26.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / node-prismjs

Package

Name
node-prismjs
Purl
pkg:deb/debian/node-prismjs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.29.0+dfsg+~1.26.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}