HIGH7.4
GHSA-gj77-59wh-66hg
Regular Expression Denial of Service (ReDoS) in Prism
Quick fix
GHSA-gj77-59wh-66hg — prismjs: upgrade to the fixed version with the command below.
npm install prismjs@1.24.0Details
Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).
### Impact
When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.
- ASCIIDoc - ERB
Other languages are __not__ affected and can be used to highlight untrusted text.
### Patches This problem has been fixed in Prism v1.24.
### References
- PrismJS/prism#2774 - PrismJS/prism#2688
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/PrismJS/prism/security/advisories/GHSA-gj77-59wh-66hg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-32723[ADVISORY]
- https://github.com/PrismJS/prism/pull/2688[WEB]
- https://github.com/PrismJS/prism/pull/2774[WEB]
- https://github.com/PrismJS/prism/commit/d85e30da6755fdbe7f8559f8e75d122297167018[WEB]
- https://github.com/PrismJS/prism[PACKAGE]
- https://www.oracle.com/security-alerts/cpujan2022.html[WEB]