Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-44270

Опубликовано: 29 сент. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

There's a flaw in the PostCSS package where it fails to properly validate the input CSS, causing commented lines to be interpreted as code. An attacker may leverage that by crafting a CSS file with comments containing CSS code in order to force PostCSS to include the malicious CSS elements in its output. An successful attack may lead to integrity impact as it may inject elements in a web page when parsing untrusted CSS input.

Меры по смягчению последствий

There's no known mitigation for this issue. Red Hat recommends to not parse untrusted CSS input using PostCSS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3io.cryostat-cryostat3Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel8Affected
Migration Toolkit for Applications 7mta/mta-cli-rhel9Fix deferred
Migration Toolkit for Applications 7mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Will not fix
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Not affected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2326998PostCSS: Improper input validation in PostCSS

EPSS

Процентиль: 54%
0.00822
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 3 года назад

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

CVSS3: 5.3
nvd
почти 3 года назад

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

msrc
6 месяцев назад

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

CVSS3: 5.3
debian
почти 3 года назад

An issue was discovered in PostCSS before 8.4.31. The vulnerability af ...

CVSS3: 5.3
github
почти 3 года назад

PostCSS line return parsing error

EPSS

Процентиль: 54%
0.00822
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2023-44270