CVE Vulnerabilities

CVE-2021-33587

Published: May 28, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.

Affected Software

Name Vendor Start Version End Version
Css-what Css-what_project 4.0.0 (including) 4.0.0 (including)
Css-what Css-what_project 5.0.0 (including) 5.0.0 (including)
Node-css-what Ubuntu bionic *
Node-css-what Ubuntu esm-apps/focal *
Node-css-what Ubuntu esm-apps/xenial *
Node-css-what Ubuntu focal *
Node-css-what Ubuntu groovy *
Node-css-what Ubuntu hirsute *
Node-css-what Ubuntu impish *
Node-css-what Ubuntu mantic *
Node-css-what Ubuntu trusty *
Node-css-what Ubuntu xenial *

References