Vulnerability Description
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prismjs | Prism | < 1.23.0 |
References
- https://github.com/PrismJS/prism/commit/c2f6a64426f44497a675cb32dccb079b3eff1609PatchThird Party Advisory
- https://github.com/PrismJS/prism/issues/2583ExploitPatchThird Party Advisory
- https://github.com/PrismJS/prism/pull/2584PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1076583ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076582ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-PRISMJS-1076581ExploitThird Party Advisory
- https://github.com/PrismJS/prism/commit/c2f6a64426f44497a675cb32dccb079b3eff1609PatchThird Party Advisory
- https://github.com/PrismJS/prism/issues/2583ExploitPatchThird Party Advisory
- https://github.com/PrismJS/prism/pull/2584PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1076583ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076582ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-PRISMJS-1076581ExploitThird Party Advisory
FAQ
What is CVE-2021-23341?
CVE-2021-23341 is a vulnerability with a CVSS score of 7.5 (HIGH). The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.
How severe is CVE-2021-23341?
CVE-2021-23341 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23341?
Check the references section above for vendor advisories and patch information. Affected products include: Prismjs Prism.