CVE-2024-21541
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Nov 13, 2024
CWE ID 94
Summary
CVE-2024-21541 is a newly disclosed vulnerability affecting all versions of the dom-iterator package. This issue permits Arbitrary Code Execution due to the use of the Function constructor without proper input sanitization. The Function constructor creates a new function body, making it essential to restrict attacker-controlled inputs to prevent potential exploitation. The risk level is comparable to allowing attacker-input to reach the eval function. Users are urged to update their packages to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.