Vulnerability Description
The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
CVSS Score
5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Postcss | Postcss | >= 7.0.0, < 7.0.36 |
References
- https://github.com/postcss/postcss/commit/8682b1e4e328432ba692bed52326e84439cec9PatchThird Party Advisory
- https://github.com/postcss/postcss/commit/b6f3e4d5a8d7504d553267f80384373af3a3dePatchThird Party Advisory
- https://lists.apache.org/thread.html/r00158f5d770d75d0655c5eef1bdbc6150531606c8f
- https://lists.apache.org/thread.html/r16e295b4f02d81b79981237d602cb0b9e59709bafa
- https://lists.apache.org/thread.html/r49afb49b38748897211b1f89c3a64dc27f90494743
- https://lists.apache.org/thread.html/r5acd89f3827ad9a9cad6d24ed93e377f7114867cd9
- https://lists.apache.org/thread.html/r8def971a66cf3e375178fbee752e1b04a812a047cc
- https://lists.apache.org/thread.html/rad5af2044afb51668b1008b389ac815a28ecea9eb7
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244795ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-POSTCSS-1090595ExploitPatchThird Party Advisory
- https://github.com/postcss/postcss/commit/8682b1e4e328432ba692bed52326e84439cec9PatchThird Party Advisory
- https://github.com/postcss/postcss/commit/b6f3e4d5a8d7504d553267f80384373af3a3dePatchThird Party Advisory
- https://lists.apache.org/thread.html/r00158f5d770d75d0655c5eef1bdbc6150531606c8f
- https://lists.apache.org/thread.html/r16e295b4f02d81b79981237d602cb0b9e59709bafa
- https://lists.apache.org/thread.html/r49afb49b38748897211b1f89c3a64dc27f90494743
FAQ
What is CVE-2021-23368?
CVE-2021-23368 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
How severe is CVE-2021-23368?
CVE-2021-23368 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23368?
Check the references section above for vendor advisories and patch information. Affected products include: Postcss Postcss.