MEDIUM5.0
GHSA-4cv2-xc5f-px8h
Denial of Service in extension "Code Highlight" (codehighlight)
Quick fix
GHSA-4cv2-xc5f-px8h — brotkrueml/codehighlight: upgrade to the fixed version with the command below.
composer require brotkrueml/codehighlight:^2.5.0Details
The codehighlight extension bundles a vulnerable version of the 3rd party JavaScript component “prism” which is known to be vulnerable against Regular expression Denial of Service (ReDoS).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/brotkrueml/codehighlight
Introduced in:
0Fixed in: 2.5.0Fix
composer require brotkrueml/codehighlight:^2.5.0References
- https://github.com/brotkrueml/codehighlight/commit/c2f05e5200f1562a3fba2de1f12ee9872f883e2c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/brotkrueml/codehighlight/2021-03-16-1.yaml[WEB]
- https://github.com/brotkrueml/codehighlight[PACKAGE]
- https://typo3.org/security/advisory/typo3-ext-sa-2021-002[WEB]