CVE-2024-21541

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 94

Summary

CVE-2024-21541 is a newly disclosed vulnerability affecting all versions of the dom-iterator package. This issue permits Arbitrary Code Execution due to the use of the Function constructor without proper input sanitization. The Function constructor creates a new function body, making it essential to restrict attacker-controlled inputs to prevent potential exploitation. The risk level is comparable to allowing attacker-input to reach the eval function. Users are urged to update their packages to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share