HIGH7.5
GHSA-cgfm-xwp7-2cvr
Sanitize-html Vulnerable To REDoS Attacks
Quick fix
GHSA-cgfm-xwp7-2cvr — sanitize-html: upgrade to the fixed version with the command below.
npm install sanitize-html@2.7.1Details
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25887[ADVISORY]
- https://github.com/apostrophecms/sanitize-html/pull/557[WEB]
- https://github.com/apostrophecms/sanitize-html/commit/b4682c12fd30e12e82fa2d9b766de91d7d2cd23c[WEB]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3008102[WEB]
- https://security.snyk.io/vuln/SNYK-JS-SANITIZEHTML-2957526[WEB]