PT-2023-7748 · Adobe · @Adobe/Css-Tools

·

CVE-2023-48631

·

Published

2023-11-16

·

Updated

2024-01-11

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions @adobe/css-tools versions 4.3.1 and earlier
Description The issue is related to an Improper Input Validation vulnerability in the CSS parser for Node.js. This vulnerability could result in a denial of service while attempting to parse CSS, allowing a remote attacker to cause a service disruption.
Recommendations For versions 4.3.1 and earlier, update to version 4.3.2 to resolve the issue.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08815
CVE-2023-48631
GHSA-PRR3-C3M5-P7Q2

Affected Products

@Adobe/Css-Tools