cbcvebase.
CVE-2023-44270
published 2023-09-29

CVE-2023-44270: An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS…

PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.82%
53.7th percentile
An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

Affected

4 ranges
VendorProductVersion rangeFixed in
debiannode-postcss< node-postcss 8.4.20+~cs8.0.23-1+deb12u1 (bookworm)node-postcss 8.4.20+~cs8.0.23-1+deb12u1 (bookworm)
msrcazl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0
postcsspostcss< 8.4.318.4.31
postcsspostcss>= 0 < 8.4.318.4.31

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.