Description
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc
, prism-rest
, prism-tap
and prism-eiffel
components.
Recommendation
Update the prismjs
package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.23.0
- Patched version(s): 1.23.0
References
Related Issues
- Prototype Pollution in lodash - CVE-2018-3721
- Stored XSS in Jupyter nbdime - CVE-2021-41134
- Cross-site Scripting in quill - CVE-2021-3163
- Prototype Pollution in async - CVE-2021-43138
- Tags:
- npm
- prismjs
Anything's wrong? Let us know Last updated on September 05, 2023