{
  "threat_severity" : "Moderate",
  "public_date" : "2024-02-24T00:00:00Z",
  "bugzilla" : {
    "description" : "sanitize-html: Information Exposure when used on the backend",
    "id" : "2266111",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2266111"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-200",
  "details" : [ "Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.", "An information exposure flaw was found in the sanitize-html package, when used on the backend with the style attribute allowed. This issue may allow an attacker to enumerate files in the system, including project dependencies, to gather details about the file system structure and dependencies of the targeted server." ],
  "affected_release" : [ {
    "product_name" : "multicluster engine for Kubernetes 2.4 for RHEL 8",
    "release_date" : "2024-06-03T00:00:00Z",
    "advisory" : "RHBA-2024:3555",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.4::el8",
    "package" : "multicluster-engine/console-mce-rhel8:v2.4.5-25"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.4 for RHEL 8",
    "release_date" : "2024-06-03T00:00:00Z",
    "advisory" : "RHBA-2024:3555",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.4::el8",
    "package" : "multicluster-engine/multicluster-engine-console-mce-rhel8:v2.4.5-25"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.5 for RHEL 9",
    "release_date" : "2024-04-10T00:00:00Z",
    "advisory" : "RHBA-2024:1775",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.5::el8",
    "package" : "multicluster-engine/console-mce-rhel9:v2.5.2-6"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.5 for RHEL 9",
    "release_date" : "2024-04-10T00:00:00Z",
    "advisory" : "RHBA-2024:1775",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.5::el8",
    "package" : "multicluster-engine/multicluster-engine-console-mce-rhel9:v2.5.2-6"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9",
    "release_date" : "2024-04-11T00:00:00Z",
    "advisory" : "RHBA-2024:1793",
    "cpe" : "cpe:/a:redhat:acm:2.10::el9",
    "package" : "rhacm2/console-rhel9:v2.10.1-3"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8",
    "release_date" : "2024-06-04T00:00:00Z",
    "advisory" : "RHBA-2024:3593",
    "cpe" : "cpe:/a:redhat:acm:2.9::el8",
    "package" : "rhacm2/console-rhel8:v2.9.4-22"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.15",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1770",
    "cpe" : "cpe:/a:redhat:openshift:4.15::el8",
    "package" : "openshift4/ose-monitoring-plugin-rhel8:v4.15.0-202404031310.p0.ge8f7503.assembly.stream.el8"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Developer Hub",
    "fix_state" : "Affected",
    "package_name" : "rhdh/rhdh-hub-rhel9",
    "cpe" : "cpe:/a:redhat:rhdh:1"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Not affected",
    "package_name" : "openshift3/ose-console",
    "cpe" : "cpe:/a:redhat:openshift:3.11"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "openshift4/ose-console",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Will not fix",
    "package_name" : "devspaces/dashboard-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Affected",
    "package_name" : "quay/quay-rhel8",
    "cpe" : "cpe:/a:redhat:quay:3"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "nodejs-redhat-cloud-services-frontend-components",
    "cpe" : "cpe:/a:redhat:satellite:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-21501\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-21501\nhttps://github.com/apostrophecms/sanitize-html/commit/c5dbdf77fe8b836d3bf4554ea39edb45281ec0b4" ],
  "name" : "CVE-2024-21501",
  "csaw" : false
}