CVE-2021-29059

A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.
Configurations

Configuration 1 (hide)

cpe:2.3:a:is-svg_project:is-svg:*:*:*:*:*:node.js:*:*

History

06 Jul 2021, 13:15

Type Values Removed Values Added
Summary A vulnerability was discovered in IS-SVG version 4.3.1 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string. A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.

25 Jun 2021, 00:49

Type Values Removed Values Added
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CPE cpe:2.3:a:is-svg_project:is-svg:*:*:*:*:*:node.js:*:*
References (MISC) https://www.npmjs.com/package/is-svg - (MISC) https://www.npmjs.com/package/is-svg - Product
References (MISC) https://github.com/sindresorhus/is-svg/releases/tag/v4.3.0 - (MISC) https://github.com/sindresorhus/is-svg/releases/tag/v4.3.0 - Release Notes, Third Party Advisory
References (MISC) https://github.com/yetingli/SaveResults/blob/main/js/is-svg.js - (MISC) https://github.com/yetingli/SaveResults/blob/main/js/is-svg.js - Third Party Advisory
References (MISC) https://github.com/yetingli/PoCs/blob/main/CVE-2021-29059/IS-SVG.md - (MISC) https://github.com/yetingli/PoCs/blob/main/CVE-2021-29059/IS-SVG.md - Exploit, Patch, Third Party Advisory

21 Jun 2021, 17:35

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-21 16:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-29059

Mitre link : CVE-2021-29059

CVE.ORG link : CVE-2021-29059


JSON object : View

Products Affected

is-svg_project

  • is-svg
CWE
CWE-770

Allocation of Resources Without Limits or Throttling