Bug 1995798 (CVE-2021-23424) - CVE-2021-23424 nodejs-ansi-html: ReDoS via crafted string
Summary: CVE-2021-23424 nodejs-ansi-html: ReDoS via crafted string
Keywords:
Status: NEW
Alias: CVE-2021-23424
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2003339 2003340 2003341
Blocks: 1995800
TreeView+ depends on / blocked
 
Reported: 2021-08-19 19:03 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-10-25 17:21 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2021-08-19 19:03:02 UTC
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.

References:
https://github.com/Tjatse/ansi-html/issues/19
https://snyk.io/vuln/SNYK-JS-ANSIHTML-1296849

Comment 1 juneau 2021-08-24 14:59:28 UTC
Setting hosted services 'notaffected.'
Affected package appears in nodejs package-lock.json (and yarn.lock) but does not appear in any source code.


Note You need to log in before you can comment on or make changes to this bug.