CVE Vulnerabilities

CVE-2023-44270

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Sep 29, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Postcss Postcss * 8.4.31 (excluding)
Discovery 1 for RHEL 9 RedHat discovery/discovery-server-rhel9:1.12.0-1 *
Discovery 1 for RHEL 9 RedHat discovery/discovery-ui-rhel9:1.12.0-1 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/nmstate-console-plugin-rhel9:v4.17.0-202411261204.p0.gbc40e56.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-networking-console-plugin-rhel9:v4.17.0-202501150934.p0.g0244dff.assembly.stream.el9 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/code-rhel9:3.18-6 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/dashboard-rhel9:3.18-10 *
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 RedHat openshift-service-mesh/kiali-rhel8:1.73.17-1 *
RHODF-4.14-RHEL-9 RedHat odf4/ocs-client-console-rhel9:v4.14.16-2 *
RHODF-4.14-RHEL-9 RedHat odf4/odf-console-rhel9:v4.14.16-1 *
RHODF-4.14-RHEL-9 RedHat odf4/odf-multicluster-console-rhel9:v4.14.16-2 *
RHODF-4.15-RHEL-9 RedHat odf4/ocs-client-console-rhel9:v4.15.12-1 *
RHODF-4.15-RHEL-9 RedHat odf4/odf-console-rhel9:v4.15.12-1 *
RHODF-4.15-RHEL-9 RedHat odf4/odf-multicluster-console-rhel9:v4.15.12-1 *
RHODF-4.16-RHEL-9 RedHat odf4/ocs-client-console-rhel9:v4.16.8-1 *
RHODF-4.16-RHEL-9 RedHat odf4/odf-console-rhel9:v4.16.8-1 *
RHODF-4.16-RHEL-9 RedHat odf4/odf-multicluster-console-rhel9:v4.16.8-1 *
RHODF-4.17-RHEL-9 RedHat odf4/ocs-client-console-rhel9:v4.17.5-1 *
RHODF-4.17-RHEL-9 RedHat odf4/odf-console-rhel9:v4.17.5-1 *
RHODF-4.17-RHEL-9 RedHat odf4/odf-multicluster-console-rhel9:v4.17.5-2 *
RHODF-4.18-RHEL-9 RedHat odf4/ocs-client-console-rhel9:v4.18.0-65 *
RHODF-4.18-RHEL-9 RedHat odf4/odf-console-rhel9:v4.18.0-65 *
RHODF-4.18-RHEL-9 RedHat odf4/odf-multicluster-console-rhel9:v4.18.0-64 *
Node-postcss Ubuntu bionic *
Node-postcss Ubuntu lunar *
Node-postcss Ubuntu mantic *
Node-postcss Ubuntu trusty *
Node-postcss Ubuntu xenial *

Potential Mitigations

References