youtube-lite icon indicating copy to clipboard operation
youtube-lite copied to clipboard

chore(deps): update dependency prismjs to 1.25.0 [security]

Open renovate[bot] opened this issue 3 years ago • 2 comments

WhiteSource Renovate

This PR contains the following updates:

Package Change
prismjs 1.23.0 -> 1.25.0

GitHub Vulnerability Alerts

CVE-2021-32723

Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).

Impact

When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.

  • ASCIIDoc
  • ERB

Other languages are not affected and can be used to highlight untrusted text.

Patches

This problem has been fixed in Prism v1.24.

References

  • PrismJS/prism#​2774
  • PrismJS/prism#​2688

CVE-2021-3801

The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • [ ] If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

renovate[bot] avatar Sep 15 '21 17:09 renovate[bot]

App preview will be available at https://ytlite-138.surge.sh

github-actions[bot] avatar Sep 15 '21 17:09 github-actions[bot]

Storybook preview will be available at https://ytlitesb-138.surge.sh

github-actions[bot] avatar Sep 15 '21 17:09 github-actions[bot]