FortAwesome / react-fontawesome

Font Awesome React component
https://fontawesome.com
MIT License
3.67k stars 264 forks source link

CVE-2021-33587 | Unknown #511

Open tickoosunny opened 2 years ago

tickoosunny commented 2 years ago

SCA Vulnerabilities:

CVE-2021-33587 | Unknown css-what is vulnerable to denial of service. The vulnerability exists due to the system not ensuring that the attribute handler has Linear Time Complexity (LTC) relative to the size of the input causing the system to overload on the resource and crashing the system.

CVE-2021-3803 | Unknown

nth-check is vulnerable to regular expression denial of service. The vulnerability exists due to an inefficient regular expression which can crash the system when parsing a malicious string.

Scan with VERACODE

Expected behavior Should not get any security issue while scanning with any tool .

NA Add any other context about the problem here.