A flaw that leads to regular expression denial of service (ReDoS) attacks was found in clean-css before 4.1.11. Upstream patch: https://github.com/jakubpawlowicz/clean-css/commit/2929bafbf8cdf7dccb24e0949c70833764fa87e3 References: https://snyk.io/vuln/npm:clean-css:20180306
Created nodejs-clean-css tracking bugs for this issue: Affects: fedora-all [bug 1553278] Affects: epel-7 [bug 1553277]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.