Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-48631

Опубликовано: 14 дек. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.

A Regular Expression Denial of Service (ReDoS) vulnerability was found in Adobe's css-tools when parsing CSS. This issue occurs due to improper input validation and may allow an attacker to use a carefully crafted input string to cause a denial of service, especially when attempting to parse CSS.

Отчет

The Regular Expression Denial of Service (ReDoS) vulnerability in css-tools, triggered by improper input validation when parsing CSS, is considered of moderate severity. While it can lead to a denial of service by causing the application to become unresponsive, the impact is limited to scenarios where an attacker can provide crafted input. Additionally, the absence of evidence of active exploitation in the wild and contextual factors, such as the software's usage, contribute to the moderate severity rating.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2css-toolsNot affected
Migration Toolkit for Applications 6mta/mta-ui-rhel9Will not fix
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Affected
Red Hat Ansible Automation Platform 2aap-cloud-ui-containerAffected
Red Hat Build of Keycloakcss-toolsNot affected
Red Hat build of OptaPlanner 8css-toolsNot affected
Red Hat Data Grid 8css-toolsNot affected
Red Hat JBoss Enterprise Application Platform 8css-toolsNot affected
Red Hat OpenShift Container Platform 4openshift4/nmstate-console-plugin-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2254559css-tools: regular expression denial of service (ReDoS) when parsing CSS

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.

msrc
около 2 лет назад

Adobe Systems Incorporated: CVE-2023-Improper Input Validation Denial of Service Vulnerability

CVSS3: 5
github
около 2 лет назад

@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость CSS-парсера для Node.js css-tools, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3