Описание
prismjs Regular Expression Denial of Service vulnerability
Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
Пакеты
Наименование
prismjs
npm
Затронутые версииВерсия исправления
< 1.25.0
1.25.0
Связанные уязвимости
CVSS3: 6.5
ubuntu
больше 4 лет назад
prism is vulnerable to Inefficient Regular Expression Complexity
CVSS3: 6.5
redhat
больше 4 лет назад
prism is vulnerable to Inefficient Regular Expression Complexity
CVSS3: 6.5
nvd
больше 4 лет назад
prism is vulnerable to Inefficient Regular Expression Complexity
CVSS3: 6.5
debian
больше 4 лет назад
prism is vulnerable to Inefficient Regular Expression Complexity