Vulnerability Description
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Color-String Project | Color-String | < 1.5.5 |
Related Weaknesses (CWE)
References
- https://github.com/Qix-/color-string/commit/0789e21284c33d89ebc4ab4ca6f759b9375aPatchThird Party Advisory
- https://github.com/yetingli/PoCs/blob/main/CVE-2021-29060/Color-String.mdExploitPatchThird Party Advisory
- https://github.com/yetingli/SaveResults/blob/main/js/color-string.jsThird Party Advisory
- https://www.npmjs.com/package/color-stringProduct
- https://github.com/Qix-/color-string/commit/0789e21284c33d89ebc4ab4ca6f759b9375aPatchThird Party Advisory
- https://github.com/yetingli/PoCs/blob/main/CVE-2021-29060/Color-String.mdExploitPatchThird Party Advisory
- https://github.com/yetingli/SaveResults/blob/main/js/color-string.jsThird Party Advisory
- https://www.npmjs.com/package/color-stringProduct
FAQ
What is CVE-2021-29060?
CVE-2021-29060 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB strin...
How severe is CVE-2021-29060?
CVE-2021-29060 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29060?
Check the references section above for vendor advisories and patch information. Affected products include: Color-String Project Color-String.