Vulnerability Description
The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Handsontable | Handsontable | < 10.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/handsontable/handsontable/issues/8752Third Party Advisory
- https://github.com/handsontable/handsontable/pull/8742PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-DOTNET-HANDSONTABLE-1726793ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1726795ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1726796ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBHANDSONTABLE-1726794ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1726797ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-HANDSONTABLE-1726770ExploitThird Party Advisory
- https://github.com/handsontable/handsontable/issues/8752Third Party Advisory
- https://github.com/handsontable/handsontable/pull/8742PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-DOTNET-HANDSONTABLE-1726793ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1726795ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1726796ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBHANDSONTABLE-1726794ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1726797ExploitThird Party Advisory
FAQ
What is CVE-2021-23446?
CVE-2021-23446 is a vulnerability with a CVSS score of 7.5 (HIGH). The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.
How severe is CVE-2021-23446?
CVE-2021-23446 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23446?
Check the references section above for vendor advisories and patch information. Affected products include: Handsontable Handsontable.