CVE-2022-21222: Regular Expression Denial of Service (ReDoS)
The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the reattr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.
Other sources
The package css-what before 2.1.3 is vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of insecure regular expression in the reattr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-21222?
CVE-2022-21222 is a vulnerability in the package css-what before version 2.1.3 that allows for Regular Expression Denial of Service (ReDoS) attacks.
How does CVE-2022-21222 affect css-what package?
CVE-2022-21222 affects the css-what package before version 2.1.3 by exploiting an insecure regular expression in the re_attr variable of index.js, allowing for ReDoS attacks via the parse function.
What is the severity of CVE-2022-21222?
CVE-2022-21222 has a severity rating of high (7.5) based on the NVD severity scoring.
How can I fix CVE-2022-21222?
To fix CVE-2022-21222, upgrade the css-what package to version 2.1.3 or later, which includes the necessary fix.
Where can I find more information about CVE-2022-21222?
You can find more information about CVE-2022-21222 on the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-21222), [Snyk](https://security.snyk.io/vuln/SNYK-JS-CSSWHAT-3035488), [GitHub](https://github.com/fb55/css-what/commit/dc510929790da6617e7aa93a616498b22f6a6b72)