Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43076
HistorySep 01, 2023 - 4:50 p.m.

Regular Expression Denial Of Service (ReDoS)

2023-09-0116:50:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
regular expression denial of service
redos
css parsing
application slowdown
vulnerability

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

20.4%

@adobe/css-tools is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability exists in index.ts due to improper input validations which allows an attacker to cause an application slowdown when parsing CSS.

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

20.4%