fix(security): force ansi-html > 0.0.8 - CVE-2021-23424 #1920
Labels
dependencies
Pull requests that update a dependency file
P1
Priority 1: Highest
Security
Related to existing or potential security vulnerabilities
Severity
High
7.5
/ 10
CVSS base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400
CVE ID
CVE-2021-23424
GHSA ID
GHSA-whgm-jr23-g3j9
Dependabot cannot update ansi-html to a non-vulnerable version
The latest possible version of ansi-html that can be installed is 0.0.7.
The earliest fixed version is 0.0.8.
Package
Affected versions
Patched version
ansi-html
(npm)
< 0.0.8
0.0.8
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
Assignees:
Labels:
The text was updated successfully, but these errors were encountered: