VDB
Sign up
MEDIUM5.0

GHSA-65xh-hh78-6454

Denial of Service in extension "Code Highlight" (codehighlight)

Quick fix

GHSA-65xh-hh78-6454 — brotkrueml/codehighlight: upgrade to the fixed version with the command below.

composer require brotkrueml/codehighlight:^2.7.0

Details

The codehighlight extension bundles a vulnerable version of the 3rd party JavaScript component “prism” which is known to be vulnerable against Regular expression Denial of Service (ReDoS).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/brotkrueml/codehighlight
Introduced in: 0Fixed in: 2.7.0
Fixcomposer require brotkrueml/codehighlight:^2.7.0

References