Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-21222

Опубликовано: 30 сент. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

РелизСтатусПримечание
bionic

released

2.1.0-1+deb10u1build0.18.04.1
devel

needs-triage

esm-apps-legacy/xenial

released

2.1.0-1ubuntu0.16.04.1~esm1
esm-apps/bionic

released

2.1.0-1+deb10u1build0.18.04.1
esm-apps/focal

released

3.2.1-1ubuntu0.1~esm1
esm-apps/jammy

not-affected

5.1.0-2
esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-apps/xenial

released

2.1.0-1ubuntu0.16.04.1~esm1
focal

ignored

end of standard support, was needed

Показывать по

EPSS

Процентиль: 73%
0.01525
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 4 года назад

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

CVSS3: 5.3
nvd
почти 4 года назад

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

CVSS3: 5.3
debian
почти 4 года назад

The package css-what before 2.1.3 are vulnerable to Regular Expression ...

CVSS3: 7.5
github
почти 4 года назад

css-what vulnerable to ReDoS due to use of insecure regular expression

EPSS

Процентиль: 73%
0.01525
Низкий

5.3 Medium

CVSS3