Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7r3r-gq8p-v9jj

Опубликовано: 23 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper handling of CSS at-rules in lettersanitizer

Impact

All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes.

This package is depended on by react-letter, therefore everyone using react-letter is also at risk.

Patches

The problem has been patched in version 1.0.2.

Workarounds

There is no workaround besides upgrading.

References

The issue was originally reported in the react-letter repository: https://github.com/mat-sz/react-letter/issues/17

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

lettersanitizer

npm
Затронутые версииВерсия исправления

< 1.0.2

1.0.2

EPSS

Процентиль: 62%
0.00431
Низкий

7.5 High

CVSS3

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended on by [react-letter](https://github.com/mat-sz/react-letter), therefore everyone using react-letter is also at risk. The problem has been patched in version 1.0.2.

EPSS

Процентиль: 62%
0.00431
Низкий

7.5 High

CVSS3

Дефекты

CWE-754