PT-2021-23969 · Jsx-Slack · Jsx-Slack
Hieki
·
Published
2021-12-17
·
Updated
2023-07-21
·
CVE-2021-43838
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
jsx-slack versions prior to 4.5.1
Description:
The issue concerns a regular expression denial-of-service (ReDoS) attack. If an attacker can put a lot of JSX elements into the
<blockquote> tag, an internal regular expression for escaping characters may consume an excessive amount of computing resources.Recommendations:
For versions prior to 4.5.1, upgrade to version 4.5.1 or later as soon as possible to patch the regex for escaping blockquote characters.
For version 4.5.1, note that while it has a patched workaround, it is still vulnerable to contents with multibyte characters, so upgrading to version 4.5.2 is recommended to fully prevent catastrophic backtracking.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jsx-Slack