HIGH
GHSA-h4hr-7fg3-h35w
Denial of service in prismjs
Quick fix
GHSA-h4hr-7fg3-h35w — prismjs: upgrade to the fixed version with the command below.
npm install prismjs@1.23.0Details
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `prism-asciidoc`, `prism-rest`, `prism-tap` and `prism-eiffel` components.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23341[ADVISORY]
- https://github.com/PrismJS/prism/issues/2583[WEB]
- https://github.com/PrismJS/prism/pull/2584[WEB]
- https://github.com/PrismJS/prism/commit/c2f6a64426f44497a675cb32dccb079b3eff1609[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1076583[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076582[WEB]
- https://snyk.io/vuln/SNYK-JS-PRISMJS-1076581[WEB]
- https://www.npmjs.com/package/prismjs[WEB]