PT-2022-17493 · Unknown · Scss-Tokenizer

Paul Bastide

·

Published

2022-07-01

·

Updated

2023-08-08

·

CVE-2022-25758

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions scss-tokenizer versions prior to 0.4.3
Description The issue is related to a Regular Expression Denial of Service (ReDoS) in the scss-tokenizer package. This occurs via the loadAnnotation() function due to the usage of insecure regex.
Recommendations For versions prior to 0.4.3, update to version 0.4.3 or later to resolve the issue. As a temporary workaround, consider disabling the loadAnnotation() function until a patch is available.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2022-25758
GHSA-7MWH-4PQV-WMR8
SNYK-JAVA-ORGWEBJARSNPM-2936782
SNYK-JS-SCSSTOKENIZER-2339884

Affected Products

Scss-Tokenizer