First published: Fri May 28 2021(Updated: )
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Css-what Project Css-what | =4.0.0 | |
Css-what Project Css-what | =5.0.0 | |
Netapp E-series Performance Analyzer | ||
npm/css-what | >=4.0.0<=5.0.0 | 5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-33587 is high with a severity value of 7.5.
The css-what package versions 4.0.0 through 5.0.0 for Node.js are affected by CVE-2021-33587.
CVE-2021-33587 impacts the css-what package for Node.js by not ensuring that attribute parsing has Linear Time Complexity relative to the size of the input.
Yes, a fix is available for CVE-2021-33587. It can be found in the css-what package version 5.0.1.
More information about CVE-2021-33587 can be found at the following references: [Reference 1](https://github.com/fb55/css-what/releases/tag/v5.0.1), [Reference 2](https://lists.debian.org/debian-lts-announce/2023/03/msg00001.html), [Reference 3](https://security.netapp.com/advisory/ntap-20210706-0007/).