Vulnerability Description
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ansi-Html Project | Ansi-Html | < 0.0.8 |
References
- https://github.com/Tjatse/ansi-html/issues/19ExploitIssue TrackingThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1567198ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-ANSIHTML-1296849ExploitThird Party Advisory
- https://github.com/Tjatse/ansi-html/issues/19ExploitIssue TrackingThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1567198ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-ANSIHTML-1296849ExploitThird Party Advisory
FAQ
What is CVE-2021-23424?
CVE-2021-23424 is a vulnerability with a CVSS score of 7.5 (HIGH). This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
How severe is CVE-2021-23424?
CVE-2021-23424 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23424?
Check the references section above for vendor advisories and patch information. Affected products include: Ansi-Html Project Ansi-Html.