MEDIUM5.0
GHSA-prr3-c3m5-p7q2
@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
Quick fix
GHSA-prr3-c3m5-p7q2 — @adobe/css-tools: upgrade to the fixed version with the command below.
npm install @adobe/css-tools@4.3.2Details
### Impact @adobe/css-tools version 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
### Patches The issue has been resolved in 4.3.2.
### Workarounds None
### References N/A
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/adobe/css-tools/security/advisories/GHSA-prr3-c3m5-p7q2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-48631[ADVISORY]
- https://github.com/adobe/css-tools/issues/211[WEB]
- https://github.com/adobe/css-tools/pull/249[WEB]
- https://github.com/adobe/css-tools/commit/472bef91bde9caab305f3f36231ad0c253581b43[WEB]
- https://github.com/adobe/css-tools[PACKAGE]