CVE Vulnerabilities

CVE-2021-33587

Published: May 28, 2021 | Modified: Mar 03, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.

Affected Software

Name Vendor Start Version End Version
Css-what Css-what_project 4.0.0 (including) 4.0.0 (including)
Css-what Css-what_project 5.0.0 (including) 5.0.0 (including)

References