CVE-2024-51757
CVE-2024-51757
9.3
CriticalPublished:
Last updated:
Source:security-advisories@github.com
Deferred
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom. Users are advised to upgrade to version 15.10.2. There are no known workarounds for this vulnerability.
References
security-advisories@github.com
https://github.com/capricorn86/happy-dom/commit/5ee0b1676d4ce20cc2a70d1c9c8d6f1e3f57efacsecurity-advisories@github.com
https://github.com/capricorn86/happy-dom/commit/d23834c232f1cf5519c9418b073f1dcec6b2f0fdsecurity-advisories@github.com
https://github.com/capricorn86/happy-dom/issues/1585security-advisories@github.com
https://github.com/capricorn86/happy-dom/pull/1586security-advisories@github.com
https://github.com/capricorn86/happy-dom/releases/tag/v15.10.2security-advisories@github.com
https://github.com/capricorn86/happy-dom/security/advisories/GHSA-96g7-g7g9-jxw8