Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-53382

16
FAUCET Score

CVE-2024-53382 affects Prism (PrismJS) up to version 1.29.0, allowing for DOM Clobbering which can lead to Cross-Site Scripting (XSS) when processing untrusted HTML input. This vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack requiring low privileges and user interaction, with potential for low impact on confidentiality and integrity. Currently, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.29.0CPE matchmatch criteria
cpe:2.3:a:prismjs:prism:*:*:*:*:*:node.js:*:*
>= 0, <= 1.29.0CPE match
cpe:2.3:a:prismjs:prism:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

4.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 31st percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (37)

npmpatch availablevia ghsa
Product: prismjsFixed in: 1.30.0
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: rhceph/grafana-rhel9:11.6.2-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: rhceph/keepalived-rhel9:2.2.8-74
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: rhceph/rhceph-7-rhel9:7-532
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: rhceph/rhceph-haproxy-rhel9:2.4.22-76
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: rhceph/rhceph-promtail-rhel9:v3.0.0-41
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: rhceph/snmp-notifier-rhel9:1.2.1-124
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: rhceph/grafana-rhel10:11.6.2-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8.1Fixed in: rhceph/grafana-rhel9:11.6.2-4
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-roxctl-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-scanner-v4-db-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-scanner-v4-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: io.apicurio-apicurio-registry
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: org.infinispan-infinispan-console
redhatvendor investigatingvia redhat_api
Product: Red Hat Developer HubFixed in: rhdh/rhdh-hub-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/ui-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: io.syndesis-syndesis-parent
redhatvendor investigatingvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: io.apicurio-apicurio-registry
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-data-science-pipelines-argo-argoexec-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/gitops-operator-bundle
redhatvendor investigatingvia redhat_api
Product: Red Hat Storage 3Fixed in: grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat Trusted Artifact SignerFixed in: rhtas/rekor-search-ui-rhel9
redhatvendor investigatingvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-api-rhel8
redhatvendor investigatingvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-console-plugin-rhel9
redhatvendor investigatingvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-db-migration-rhel8
redhatvendor investigatingvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-ui-rhel8
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-central-db-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-rhel8-operator
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 6Fixed in: rhceph/rhceph-6-dashboard-rhel9

Vendor Advisories (2)

npmGHSA-x7hr-w5r2-h6wgmedium

PrismJS DOM Clobbering vulnerability

Mar 3, 2025
redhatCVE-2024-53382Moderate

prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin

Mar 3, 2025

References

gist.github.com / jackfromeast/aeb128e44f05f95828a1a824708df660
ExploitPatchThird Party Advisory
github.com / PrismJS/prism/blob/59e5a3471377057de1f401ba38337aca27b80e03/prism.js
Product