Junglewise Threat Intelligence

CVE-2024-43370: gettext.js Cross-site Scripting in plural form parsing

CVE-2024-43370 · Severity: low · CVSS 3.1 · Published 2024-08-15

Vendors: npm.

Executive brief

gettext.js is a JavaScript library that processes translation files (PO format) to localize web applications. The library fails to properly sanitize plural form definitions when parsing corrupted or malicious .po files, allowing attackers to inject arbitrary JavaScript code that executes in users' browsers. This could lead to session hijacking, credential theft, or defacement of the web application.

Technical details

The vulnerability is a Cross-site Scripting (XSS) flaw in gettext.js's handling of plural form definitions within .po dictionary files. The root cause is insufficient input validation/sanitization when processing the plural form syntax; if a .po file contains malicious JavaScript in the plural rule definitions, it will be executed without proper escaping. The attack requires a compromised or man-in-the-middle scenario where an attacker can supply a malicious .po file to an application using gettext.js. No user interaction is needed beyond the application loading the poisoned translation file. The vulnerability affects all versions prior to 2.0.3, which introduces proper sanitization of plural form inputs. A workaround is to ensure strict control over the origin and integrity of translation catalog sources.

Affected products

  • gettext.js gettext.js <2.0.3

Timeline

  • 2024-08-15: disclosed: Security advisory GHSA-vwhg-jwr4-vxgg published
  • 2024-08-15: patched: Fix available in version 2.0.3

References