Vulnerability Description
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Browserslist Project | Browserslist | >= 4.0.0, < 4.16.5 |
Related Weaknesses (CWE)
References
- https://github.com/browserslist/browserslist/blob/e82f32d1d4100d6bc79ea0b6b6a2d2Broken Link
- https://github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad9608PatchThird Party Advisory
- https://github.com/browserslist/browserslist/pull/593Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1277182ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194ExploitPatchThird Party Advisory
- https://github.com/browserslist/browserslist/blob/e82f32d1d4100d6bc79ea0b6b6a2d2Broken Link
- https://github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad9608PatchThird Party Advisory
- https://github.com/browserslist/browserslist/pull/593Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1277182ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194ExploitPatchThird Party Advisory
FAQ
What is CVE-2021-23364?
CVE-2021-23364 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
How severe is CVE-2021-23364?
CVE-2021-23364 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23364?
Check the references section above for vendor advisories and patch information. Affected products include: Browserslist Project Browserslist.