CVE-2020-27511: High severity prototype vulnerability
Published Jun 21, 2021
·Updated
An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags.
Affected Software
1 affected component
prototypejs Prototype=1.7.3
Event History
Jun 21, 2021
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-27511?
CVE-2020-27511 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-27511?
To fix CVE-2020-27511, upgrade the Prototype JavaScript Framework to a version beyond 1.7.3.
3
What is the impact of exploiting CVE-2020-27511?
Exploiting CVE-2020-27511 can lead to a Regular Expression Denial of Service (ReDOS), potentially degrading application performance.
4
Is my application at risk if it uses Prototype 1.7.3 regarding CVE-2020-27511?
Yes, if your application uses Prototype 1.7.3, it is at risk due to the vulnerability found in stripTags and unescapeHTML components.
5
What components are affected by CVE-2020-27511?
CVE-2020-27511 affects the stripTags and unescapeHTML components of the Prototype JavaScript Framework.