First published: Thu Feb 18 2021(Updated: )
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `prism-asciidoc`, `prism-rest`, `prism-tap` and `prism-eiffel` components.
Credit: report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
npm/prismjs | <1.23.0 | 1.23.0 |
Prismjs Prism | <1.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23341 is a vulnerability in the package prismjs before version 1.23.0 that allows Regular Expression Denial of Service (ReDoS) attacks.
Regular Expression Denial of Service (ReDoS) is a type of vulnerability where a maliciously crafted input can cause a regular expression to consume significant amount of time, leading to denial of service.
CVE-2021-23341 affects prismjs before version 1.23.0, specifically impacting the `prism-asciidoc`, `prism-rest`, `prism-tap`, and `prism-eiffel` components.
CVE-2021-23341 has a severity rating of 7.5 (high).
To fix the vulnerability CVE-2021-23341, update the prismjs package to version 1.23.0 or later.