QID 982273
QID 982273: Nodejs (npm) Security Update for postcss (GHSA-hwj9-h5mp-3pm3)
The npm package `postcss` from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hwj9-h5mp-3pm3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-hwj9-h5mp-3pm3 -
github.com/advisories/GHSA-hwj9-h5mp-3pm3
CVEs related to QID 982273
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hwj9-h5mp-3pm3 | postcss |
|