CVE-2023-48631
published 2023-12-14CVE-2023-48631: @adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.12%
62.5th percentile
@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | css-tools | < 4.3.2 | 4.3.2 |
| adobe | css-tools | >= 0 < 4.3.2 | 4.3.2 |
| adobe | not_a_product | <= 4.3.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
osv·2023-11-30
CVE-2023-48631 [MEDIUM] @adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
### Impact
@adobe/css-tools version 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
### Patches
The issue has been resolved in 4.3.2.
### Workarounds
None
### References
N/A
GHSA
@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
ghsa·2023-11-30
CVE-2023-48631 [MEDIUM] CWE-1333 @adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
### Impact
@adobe/css-tools version 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
### Patches
The issue has been resolved in 4.3.2.
### Workarounds
None
### References
N/A
Red Hat
css-tools: regular expression denial of service (ReDoS) when parsing CSS
vendor_redhat·2023-12-14·CVSS 5.3
CVE-2023-48631 [MEDIUM] CWE-1333 css-tools: regular expression denial of service (ReDoS) when parsing CSS
css-tools: regular expression denial of service (ReDoS) when parsing CSS
@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
A Regular Expression Denial of Service (ReDoS) vulnerability was found in Adobe's css-tools when parsing CSS. This issue occurs due to improper input validation and may allow an attacker to use a carefully crafted input string to cause a denial of service, especially when attempting to parse CSS.
Statement: The Regular Expression Denial of Service (ReDoS) vulnerability in css-tools, triggered by improper input validation when parsing CSS, is considered of moderate severity. While it can lead to a denial of service by causing the application to
No detection rules found.
No public exploits indexed.
2023-12-14
Published