GHSA-7r3r-gq8p-v9jj

    Dashboard / Vulnerabilities / GHSA-7r3r-gq8p-v9jj

    GHSA-7r3r-gq8p-v9jj

    Published: 23 Jun 2022Last Modified: 8 Nov 2023

    Summary: Improper handling of CSS at-rules in lettersanitizer

    Details: ### Impact All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended on by [react-letter](https://github.com/mat-sz/react-letter), therefore everyone using react-letter is also at risk. ### Patches The problem has been patched in version 1.0.2. ### Workarounds There is no workaround besides upgrading. ### References The issue was originally reported in the react-letter repository: https://github.com/mat-sz/react-letter/issues/17 ### For more information If you have any questions or comments about this advisory: * Open an issue in [lettersanitizer](https://github.com/mat-sz/lettersanitizer/issues) * Email me at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: lettersanitizer

    Purl: pkg:npm/lettersanitizer

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.0.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7r3r-gq8p-v9jj | CVE-DB