Описание
lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes. This package is depended on by react-letter, therefore everyone using react-letter is also at risk. The problem has been patched in version 1.0.2.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.2 (исключая)
cpe:2.3:a:lettersanitizer_project:lettersanitizer:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 62%
0.00431
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-754
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Improper handling of CSS at-rules in lettersanitizer
EPSS
Процентиль: 62%
0.00431
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-754