CVE-2021-3801
published 2021-09-15CVE-2021-3801: prism is vulnerable to Inefficient Regular Expression Complexity
PriorityP424medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.04%
60.3th percentile
prism is vulnerable to Inefficient Regular Expression Complexity
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-prismjs | < node-prismjs 1.25.0+dfsg-1 (bookworm) | node-prismjs 1.25.0+dfsg-1 (bookworm) |
| prismjs | prism | < 1.25.0 | 1.25.0 |
| prismjs | prismjs_prism | >= 0 < 1.25.0 | 1.25.0 |
| prismjs | prismjs_prism | unspecified – 1.24.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs-prismjs: ReDoS vulnerability
vendor_redhat·2021-09-11·CVSS 6.5
CVE-2021-3801 [MEDIUM] CWE-400 nodejs-prismjs: ReDoS vulnerability
nodejs-prismjs: ReDoS vulnerability
prism is vulnerable to Inefficient Regular Expression Complexity
Insufficient Regular Expression Complexity in prismjs leads to a Regular Expression Denial of Service (ReDoS) attack. An unauthenticated attacker can exploit this flaw to cause an application to consume an excess amount of CPU by providing a crafted HTML comment as input. This can result in a denial of service attack.
Statement: OpenShift Container Platform (OCP) grafana-container does package a vulnerable verison of prismjs. However due to the instance being read only and behind OpenShift OAuth, it has been given a Low impact. Additionally it has been marked as wont-fix at this time and may be fixed in a future release.
Just as OCP, OpenShift ServiceMesh (OSSM) components are behind Ope
Debian
CVE-2021-3801: node-prismjs - prism is vulnerable to Inefficient Regular Expression Complexity
vendor_debian·2021·CVSS 6.5
CVE-2021-3801 [MEDIUM] CVE-2021-3801: node-prismjs - prism is vulnerable to Inefficient Regular Expression Complexity
prism is vulnerable to Inefficient Regular Expression Complexity
Scope: local
bookworm: resolved (fixed in 1.25.0+dfsg-1)
bullseye: resolved (fixed in 1.23.0+dfsg-1+deb11u1)
forky: resolved (fixed in 1.25.0+dfsg-1)
sid: resolved (fixed in 1.25.0+dfsg-1)
trixie: resolved (fixed in 1.25.0+dfsg-1)
GHSA
prismjs Regular Expression Denial of Service vulnerability
ghsa·2021-09-20
CVE-2021-3801 [MEDIUM] CWE-400 prismjs Regular Expression Denial of Service vulnerability
prismjs Regular Expression Denial of Service vulnerability
Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
OSV
prismjs Regular Expression Denial of Service vulnerability
osv·2021-09-20
CVE-2021-3801 [MEDIUM] prismjs Regular Expression Denial of Service vulnerability
prismjs Regular Expression Denial of Service vulnerability
Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
OSV
CVE-2021-3801: prism is vulnerable to Inefficient Regular Expression Complexity
osv·2021-09-15·CVSS 6.5
CVE-2021-3801 [MEDIUM] CVE-2021-3801: prism is vulnerable to Inefficient Regular Expression Complexity
prism is vulnerable to Inefficient Regular Expression Complexity
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-15
Published