First published: Wed Apr 28 2021(Updated: )
Browserslist is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) during parsing of queries. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
Credit: report@snyk.io report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Browserslist Project Browserslist | >=4.0.0<4.16.5 | |
npm/browserslist | >=4.0.0<4.16.5 | 4.16.5 |
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23364 is a vulnerability in the package browserslist from version 4.0.0 to 4.16.5 that allows for regular expression denial of service (ReDoS) attacks.
CVE-2021-23364 has a severity score of 5.3 out of 10, which is considered medium.
CVE-2021-23364 affects Browserslist versions 4.0.0 to 4.16.5, and can be exploited by sending specially-crafted requests to cause a denial of service.
To fix CVE-2021-23364, you should update Browserslist to version 4.16.6 or later.
You can find more information about CVE-2021-23364 on the NIST National Vulnerability Database (NVD) website.