Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1wcnIzLWMzbTUtcDdxMs4AA3d1
@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
Impact
@adobe/css-tools version 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
Patches
The issue has been resolved in 4.3.2.
Workarounds
None
References
N/A
Permalink: https://github.com/advisories/GHSA-prr3-c3m5-p7q2JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcnIzLWMzbTUtcDdxMs4AA3d1
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 year ago
Updated: 12 months ago
CVSS Score: 5.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Identifiers: GHSA-prr3-c3m5-p7q2, CVE-2023-48631
References:
- https://github.com/adobe/css-tools/security/advisories/GHSA-prr3-c3m5-p7q2
- https://github.com/adobe/css-tools/issues/211
- https://github.com/adobe/css-tools/pull/249
- https://github.com/adobe/css-tools/commit/472bef91bde9caab305f3f36231ad0c253581b43
- https://nvd.nist.gov/vuln/detail/CVE-2023-48631
- https://github.com/advisories/GHSA-prr3-c3m5-p7q2
Blast Radius: 27.7
Affected Packages
npm:@adobe/css-tools
Dependent packages: 35Dependent repositories: 350,800
Downloads: 45,768,266 last month
Affected Version Ranges: < 4.3.2
Fixed in: 4.3.2
All affected versions: 4.0.0, 4.0.1, 4.0.2, 4.1.0, 4.2.0, 4.3.0, 4.3.1
All unaffected versions: 4.3.2, 4.3.3, 4.4.0