The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-PRISMJS-1076581 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076582 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1076583 | third party advisory exploit |
https://github.com/PrismJS/prism/commit/c2f6a64426f44497a675cb32dccb079b3eff1609 | third party advisory patch |
https://github.com/PrismJS/prism/issues/2583 | exploit third party advisory patch |
https://github.com/PrismJS/prism/pull/2584 | third party advisory patch |