Junglewise Threat Intelligence

CVE-2023-48631: Adobe css-tools ReDoS in CSS parsing

CVE-2023-48631 · Severity: low · CVSS 3.1 · Published 2023-11-30

Vendors: Adobe, npm.

Executive brief

@adobe/css-tools is a JavaScript library used to parse and process CSS stylesheets. An inefficient regular expression in the library can be exploited with specially crafted CSS input to cause excessive CPU consumption, leading to denial of service. Attackers with the ability to supply CSS input to an application using this library can trigger the vulnerability without authentication, though fixing the issue requires applying a patch.

Technical details

The vulnerability is a ReDoS (regular expression denial of service) caused by improper input validation and an inefficient regular expression with exponential worst-case complexity (CWE-1333, CWE-20). An authenticated attacker can send a network request with malicious CSS input to trigger the vulnerable regex, causing the parsing function to consume excessive CPU and leading to a denial of service. According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C), the attack requires low privileges and network access. The issue is resolved in version 4.3.2; all versions 4.3.1 and earlier are affected.

Affected products

  • Adobe css-tools 4.3.1 and earlier

Timeline

  • 2023-11-30: disclosed
  • 2023-12-14: patched: Fixed in version 4.3.2

References

Related threats