7.5
CVSSv3

CVE-2022-25887

Published: 30/08/2022 Updated: 08/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The package sanitize-html prior to 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apostrophecms sanitize-html

Vendor Advisories

Debian Bug report logs - #1019219 node-sanitize-html: CVE-2022-25887 Package: src:node-sanitize-html; Maintainer for src:node-sanitize-html is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 5 Sep 2022 19:57:02 UTC Severit ...
Synopsis Moderate: Red Hat Advanced Cluster Management 262 security update and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 262 GeneralAvailability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security i ...
The package sanitize-html before 271 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal ...