CVE-2021-23341: Regular Expression Denial of Service (ReDoS)
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `prism-asciidoc`, `prism-rest`, `prism-tap` and `prism-eiffel` components.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23341?
CVE-2021-23341 is a vulnerability in the package prismjs before version 1.23.0 that allows Regular Expression Denial of Service (ReDoS) attacks.
What is Regular Expression Denial of Service (ReDoS)?
Regular Expression Denial of Service (ReDoS) is a type of vulnerability where a maliciously crafted input can cause a regular expression to consume significant amount of time, leading to denial of service.
How does CVE-2021-23341 affect prismjs?
CVE-2021-23341 affects prismjs before version 1.23.0, specifically impacting the `prism-asciidoc`, `prism-rest`, `prism-tap`, and `prism-eiffel` components.
What is the severity rating of CVE-2021-23341?
CVE-2021-23341 has a severity rating of 7.5 (high).
How can I fix the vulnerability CVE-2021-23341?
To fix the vulnerability CVE-2021-23341, update the prismjs package to version 1.23.0 or later.