7.5
CVSSv3

CVE-2021-33587

Published: 28/05/2021 Updated: 03/03/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The css-what package 4.0.0 up to and including 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

css-what project css-what 4.0.0

css-what project css-what 5.0.0

netapp e-series performance analyzer -

Vendor Advisories

Debian Bug report logs - #1032188 node-css-what: CVE-2022-21222 Package: node-css-what; Maintainer for node-css-what is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-css-what is src:node-css-what (PTS, buildd, popcon) Reported by: Bastien Roucariès <bastienroucaries@cyufr ...
Debian Bug report logs - #989264 CVE-2021-33587 Package: node-css-what; Maintainer for node-css-what is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-css-what is src:node-css-what (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 30 May 2 ...