CVE-2021-23382
26.04.2021, 16:15
The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).Enginsight
Vendor | Product | Version |
---|---|---|
postcss | postcss | 𝑥 < 7.0.36 |
postcss | postcss | 8.0.0 ≤ 𝑥 < 8.2.13 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References