CVE-2021-32723
published 2021-06-28CVE-2021-32723: Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.43%
69.9th percentile
Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_express | < 21.1.4 | 21.1.4 |
| prismjs | prism | < 1.24 | 1.24 |
| prismjs | prism | < 1.24.0 | 1.24.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_redhat7.4HIGH
vendor_oracle3.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (Prism) — CVE-2021-32723
vendor_oracle·2022-01-15·CVSS 3.5
CVE-2021-32723 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Application Express (Prism) — CVE-2021-32723
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (Prism) vulnerability
CVE: CVE-2021-32723
CVSS: 3.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
npm-prismjs: a malicious (long) string will take a long time to highlight may result in ReDoS
vendor_redhat·2021-06-28·CVSS 7.4
CVE-2021-32723 [HIGH] CWE-400 npm-prismjs: a malicious (long) string will take a long time to highlight may result in ReDoS
npm-prismjs: a malicious (long) string will take a long time to highlight may result in ReDoS
Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.
A flaw was found in npm-prismjs. An attacker can craft a string that will take a very long time to highlight when used to work with un-trusted text resulting in ReDoS.
This can affect the system availability. There is no known risk o
OSV
Regular Expression Denial of Service (ReDoS) in Prism
osv·2021-06-28
CVE-2021-32723 [HIGH] Regular Expression Denial of Service (ReDoS) in Prism
Regular Expression Denial of Service (ReDoS) in Prism
Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).
### Impact
When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.
- ASCIIDoc
- ERB
Other languages are __not__ affected and can be used to highlight untrusted text.
### Patches
This problem has been fixed in Prism v1.24.
### References
- PrismJS/prism#2774
- PrismJS/prism#2688
GHSA
Regular Expression Denial of Service (ReDoS) in Prism
ghsa·2021-06-28
CVE-2021-32723 [HIGH] CWE-400 Regular Expression Denial of Service (ReDoS) in Prism
Regular Expression Denial of Service (ReDoS) in Prism
Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).
### Impact
When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.
- ASCIIDoc
- ERB
Other languages are __not__ affected and can be used to highlight untrusted text.
### Patches
This problem has been fixed in Prism v1.24.
### References
- PrismJS/prism#2774
- PrismJS/prism#2688
OSV
CVE-2021-32723: Prism is a syntax highlighting library
osv·2021-06-28·CVSS 6.5
CVE-2021-32723 [MEDIUM] CVE-2021-32723: Prism is a syntax highlighting library
Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/PrismJS/prism/pull/2688https://github.com/PrismJS/prism/pull/2774https://github.com/PrismJS/prism/security/advisories/GHSA-gj77-59wh-66hghttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://github.com/PrismJS/prism/pull/2688https://github.com/PrismJS/prism/pull/2774https://github.com/PrismJS/prism/security/advisories/GHSA-gj77-59wh-66hghttps://www.oracle.com/security-alerts/cpujan2022.html
2021-06-28
Published