QID 982171
QID 982171: Nodejs (npm) Security Update for prismjs (GHSA-hqhp-5p83-hx96)
The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hqhp-5p83-hx96 for updates pertaining to this vulnerability.
Vendor References
- GHSA-hqhp-5p83-hx96 -
github.com/advisories/GHSA-hqhp-5p83-hx96
CVEs related to QID 982171
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hqhp-5p83-hx96 | prismjs |
|