1 results (0.001 seconds)

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

28 May 2021 — The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input. El paquete css-what versión 4.0.0 hasta la versión 5.0.0 para Node.js no asegura que el análisis sintáctico de atributos tenga una complejidad de tiempo lineal en relación con el tamaño de la entrada It was discovered that css-what incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file,... • https://github.com/fb55/css-what/releases/tag/v5.0.1 •