Name | CVE-2021-23364 |
Description | The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 987792 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
node-browserslist (PTS) | bullseye | 4.16.3+~cs5.4.72-3 | fixed |
| bookworm | 4.21.4+~cs6.1.17-2 | fixed |
| sid, trixie | 4.23.0+~cs6.1.32-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[buster] - node-browserslist <ignored> (Minor issue; risky backport with regression potential)
https://github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad96083c6709b02d98
https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194
https://github.com/browserslist/browserslist/pull/593