CVE-2021-23368
published 2021-04-12CVE-2021-23368: The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
3.54%
88.1th percentile
The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-postcss | < node-postcss 8.2.1+~cs5.3.23-6 (bookworm) | node-postcss 8.2.1+~cs5.3.23-6 (bookworm) |
| postcss | postcss | >= 7.0.0 < unspecified | unspecified |
| postcss | postcss | >= 7.0.0 < 7.0.36 | 7.0.36 |
| postcss | postcss | >= 7.0.0 < 7.0.36 | 7.0.36 |
| postcss | postcss | >= 8.0.0 < 8.2.10 | 8.2.10 |
| postcss | postcss | >= 8.0.0 < 8.2.10 | 8.2.10 |
| postcss | postcss | >= unspecified < 8.2.10 | 8.2.10 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Regular Expression Denial of Service in postcss
ghsa·2021-05-10
CVE-2021-23368 [MEDIUM] CWE-400 Regular Expression Denial of Service in postcss
Regular Expression Denial of Service in postcss
The npm package `postcss` from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
OSV
Regular Expression Denial of Service in postcss
osv·2021-05-10
CVE-2021-23368 [MEDIUM] Regular Expression Denial of Service in postcss
Regular Expression Denial of Service in postcss
The npm package `postcss` from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
OSV
CVE-2021-23368: The package postcss from 7
osv·2021-04-12·CVSS 5.3
CVE-2021-23368 [MEDIUM] CVE-2021-23368: The package postcss from 7
The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
Red Hat
nodejs-postcss: Regular expression denial of service during source map parsing
vendor_redhat·2021-04-12·CVSS 5.3
CVE-2021-23368 [MEDIUM] CWE-400 nodejs-postcss: Regular expression denial of service during source map parsing
nodejs-postcss: Regular expression denial of service during source map parsing
The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
A regular expression denial of service (ReDoS) vulnerability was found in the npm library `postcss`. When parsing a supplied CSS string, if it contains an unexpected value then as the supplied CSS grows in length it will take an ever increasing amount of time to process. An attacker can use this vulnerability to potentially craft a malicious a long CSS value to process resulting in a denial of service.
Statement: In Red Hat OpenShift Container Platform (RHOCP), OpenShift ServiceMesh (OSSM) and Red Hat Advanced Cluster Management for Kubernetes (RHACM) the affected containe
Debian
CVE-2021-23368: node-postcss - The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expre...
vendor_debian·2021·CVSS 5.3
CVE-2021-23368 [MEDIUM] CVE-2021-23368: node-postcss - The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expre...
The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
Scope: local
bookworm: resolved (fixed in 8.2.1+~cs5.3.23-6)
bullseye: resolved (fixed in 8.2.1+~cs5.3.23-6)
forky: resolved (fixed in 8.2.1+~cs5.3.23-6)
sid: resolved (fixed in 8.2.1+~cs5.3.23-6)
trixie: resolved (fixed in 8.2.1+~cs5.3.23-6)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/postcss/postcss/commit/8682b1e4e328432ba692bed52326e84439cec9e4https://github.com/postcss/postcss/commit/b6f3e4d5a8d7504d553267f80384373af3a3dec5https://lists.apache.org/thread.html/r00158f5d770d75d0655c5eef1bdbc6150531606c8f8bcb778f0627be%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r16e295b4f02d81b79981237d602cb0b9e59709bafaa73ac98be7cef1%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r49afb49b38748897211b1f89c3a64dc27f9049474322b05715695aab%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r5acd89f3827ad9a9cad6d24ed93e377f7114867cd98cfba616c6e013%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r8def971a66cf3e375178fbee752e1b04a812a047cc478ad292007e33%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/rad5af2044afb51668b1008b389ac815a28ecea9eb75ae2cab5a00ebb%40%3Ccommits.myfaces.apache.org%3Ehttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244795https://snyk.io/vuln/SNYK-JS-POSTCSS-1090595https://github.com/postcss/postcss/commit/8682b1e4e328432ba692bed52326e84439cec9e4https://github.com/postcss/postcss/commit/b6f3e4d5a8d7504d553267f80384373af3a3dec5https://lists.apache.org/thread.html/r00158f5d770d75d0655c5eef1bdbc6150531606c8f8bcb778f0627be%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r16e295b4f02d81b79981237d602cb0b9e59709bafaa73ac98be7cef1%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r49afb49b38748897211b1f89c3a64dc27f9049474322b05715695aab%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r5acd89f3827ad9a9cad6d24ed93e377f7114867cd98cfba616c6e013%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r8def971a66cf3e375178fbee752e1b04a812a047cc478ad292007e33%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/rad5af2044afb51668b1008b389ac815a28ecea9eb75ae2cab5a00ebb%40%3Ccommits.myfaces.apache.org%3Ehttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244795https://snyk.io/vuln/SNYK-JS-POSTCSS-1090595
2021-04-12
Published