You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
mend-bolt-for-githubbot
changed the title
CVE-2023-48631 (Medium) detected in css-tools-4.0.1.tgz
CVE-2023-48631 (High) detected in css-tools-4.0.1.tgz
Apr 22, 2024
CVE-2023-48631 - High Severity Vulnerability
CSS parser / stringifier
Library home page: https://registry.npmjs.org/@adobe/css-tools/-/css-tools-4.0.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/@adobe/css-tools/package.json
Dependency Hierarchy:
Found in HEAD commit: 74bd54478af041f17629534d67e4f747a9745d6a
Found in base branch: develop
@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
Publish Date: 2023-12-14
URL: CVE-2023-48631
Base Score Metrics:
Type: Upgrade version
Origin: @adobe/css-tools
Release Date: 2023-12-14
Fix Resolution: @adobe/css-tools - 4.3.2
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: