UBUNTU-CVE-2024-53382

Source
https://ubuntu.com/security/CVE-2024-53382
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-53382.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-53382
Related
Published
2025-03-03T07:15:00Z
Modified
2025-03-05T05:28:53Z
Summary
[none]
Details

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

References

Affected packages

Ubuntu:20.04:LTS / node-prismjs

Package

Name
node-prismjs
Purl
pkg:deb/ubuntu/node-prismjs@1.11.0+dfsg-3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.11.0+dfsg-2
1.11.0+dfsg-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / node-prismjs

Package

Name
node-prismjs
Purl
pkg:deb/ubuntu/node-prismjs@1.27.0+dfsg+~1.26.0-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.23.0+dfsg-1
1.25.0+dfsg-1
1.27.0+dfsg+~1.26.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / node-prismjs

Package

Name
node-prismjs
Purl
pkg:deb/ubuntu/node-prismjs@1.29.0+dfsg+~1.26.0-1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.29.0+dfsg+~1.26.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / node-prismjs

Package

Name
node-prismjs
Purl
pkg:deb/ubuntu/node-prismjs@1.29.0+dfsg+~1.26.0-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.29.0+dfsg+~1.26.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}