NodeJS/postcss/8.4.5
Tool for transforming styles with JS plugins
https://www.npmjs.com/package/postcss
MIT
1 Security Vulnerabilities
PostCSS line return parsing error
Published date: 2023-09-30T00:31:10Z
CVE: CVE-2023-44270
Links:
- https://nvd.nist.gov/vuln/detail/CVE-2023-44270
- https://github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5
- https://github.com/postcss/postcss/blob/main/lib/tokenize.js#L25
- https://github.com/postcss/postcss/releases/tag/8.4.31
- https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- https://github.com/github/advisory-database/issues/2820
An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r
discrepancies, as demonstrated by @font-face{ font:(\r/*);}
in a rule.
This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.
Affected versions:
["0.1.0", "0.2.0", "0.3.0", "0.3.1", "0.3.2", "0.3.3", "0.3.4", "0.3.5", "1.0.0", "2.0.0", "2.1.0", "2.1.1", "2.1.2", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.2.5", "2.2.6", "3.0.0", "3.0.1", "3.0.2", "3.0.3", "3.0.4", "3.0.5", "3.0.6", "3.0.7", "4.0.0", "4.0.1", "4.0.2", "4.0.3", "4.0.4", "4.0.5", "4.0.6", "4.1.0", "4.1.1", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "4.1.12", "4.1.13", "4.1.14", "4.1.15", "4.1.16", "5.0.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.0.19", "5.0.20", "5.0.21", "5.1.0", "5.1.1", "5.1.2", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "5.2.9", "5.2.10", "5.2.11", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "5.2.18", "6.0.13", "6.0.14", "6.0.15", "6.0.16", "6.0.17", "6.0.18", "6.0.19", "6.0.20", "6.0.21", "6.0.22", "6.0.23", "7.0.0", "7.0.1", "7.0.2", "7.0.3", "7.0.4", "7.0.5", "7.0.6", "7.0.7", "7.0.8", "7.0.9", "7.0.10", "7.0.11", "7.0.12", "7.0.13", "7.0.14", "7.0.15", "7.0.16", "7.0.17", "7.0.18", "7.0.19", "7.0.20", "7.0.21", "7.0.22", "7.0.23", "7.0.24", "7.0.25", "7.0.26", "7.0.27", "7.0.28", "7.0.29", "7.0.30", "7.0.31", "7.0.32", "8.0.0", "8.0.1", "8.0.2", "8.0.3", "7.0.33", "8.0.4", "7.0.34", "8.0.5", "8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.1.0", "7.0.35", "8.1.1", "8.1.2", "8.1.3", "8.1.4", "8.1.5", "8.1.6", "8.1.7", "8.1.8", "8.1.9", "8.1.10", "8.1.11", "8.1.12", "8.1.13", "8.1.14", "8.2.0", "8.2.1", "8.2.2", "8.2.3", "8.2.4", "8.2.5", "8.2.6", "8.2.7", "8.2.8", "8.2.9", "8.2.10", "8.2.11", "8.2.12", "8.2.13", "8.2.14", "8.2.15", "8.3.0", "8.3.1", "7.0.36", "8.3.2", "8.3.3", "8.3.4", "8.3.5", "8.3.6", "8.3.7", "7.0.37", "7.0.38", "8.3.8", "7.0.39", "8.3.9", "8.3.10", "8.3.11", "8.4.0", "8.4.1", "8.4.2", "8.4.3", "8.4.4", "8.4.5", "8.4.6", "8.4.7", "8.4.8", "8.4.9", "8.4.10", "8.4.11", "8.4.12", "8.4.13", "8.4.14", "8.4.15", "8.4.16", "8.4.17", "8.4.18", "8.4.19", "8.4.20", "8.4.21", "8.4.22", "8.4.23", "8.4.24", "8.4.25", "8.4.26", "8.4.27", "8.4.28", "8.4.29", "8.4.30"]
Secure versions:
[8.4.31, 8.4.32, 8.4.33, 8.4.34, 8.4.35, 8.4.36, 8.4.37, 8.4.38]
Recommendation:
Update to version 8.4.38.
252 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
7.0.31 | MIT | 3 | 2020-05-26 - 02:13 | almost 4 years |
7.0.30 | MIT | 3 | 2020-05-11 - 14:00 | about 4 years |
7.0.29 | MIT | 3 | 2020-05-04 - 14:16 | about 4 years |
7.0.28 | MIT | 3 | 2020-05-02 - 14:40 | about 4 years |
7.0.27 | MIT | 3 | 2020-02-18 - 02:59 | about 4 years |
7.0.26 | MIT | 3 | 2019-12-31 - 00:11 | over 4 years |
7.0.25 | MIT | 3 | 2019-12-16 - 19:16 | over 4 years |
7.0.24 | MIT | 3 | 2019-12-06 - 18:54 | over 4 years |
7.0.23 | MIT | 3 | 2019-11-18 - 22:36 | over 4 years |
7.0.22 | MIT | 3 | 2019-11-18 - 22:29 | over 4 years |
7.0.21 | MIT | 3 | 2019-10-25 - 15:55 | over 4 years |
7.0.20 | MIT | 3 | 2019-10-24 - 15:12 | over 4 years |
7.0.19 | MIT | 3 | 2019-10-24 - 12:44 | over 4 years |
7.0.18 | MIT | 3 | 2019-09-05 - 23:20 | over 4 years |
7.0.17 | MIT | 3 | 2019-06-05 - 16:38 | almost 5 years |
7.0.16 | MIT | 3 | 2019-05-04 - 18:59 | about 5 years |
7.0.15 | MIT | 3 | 2019-05-04 - 05:42 | about 5 years |
7.0.14 | MIT | 3 | 2019-01-22 - 14:16 | over 5 years |
7.0.13 | MIT | 3 | 2019-01-15 - 18:09 | over 5 years |
7.0.12 | MIT | 3 | 2019-01-15 - 16:33 | over 5 years |
7.0.11 | MIT | 3 | 2019-01-12 - 16:14 | over 5 years |
7.0.10 | MIT | 3 | 2019-01-11 - 20:15 | over 5 years |
7.0.9 | MIT | 3 | 2019-01-11 - 14:18 | over 5 years |
7.0.8 | MIT | 3 | 2019-01-08 - 12:04 | over 5 years |
7.0.7 | MIT | 3 | 2018-12-17 - 02:04 | over 5 years |
7.0.6 | MIT | 3 | 2018-11-18 - 01:34 | over 5 years |
7.0.5 | MIT | 3 | 2018-10-02 - 13:14 | over 5 years |
7.0.4 | MIT | 3 | 2018-09-27 - 06:17 | over 5 years |
7.0.3 | MIT | 3 | 2018-09-25 - 22:20 | over 5 years |
7.0.2 | MIT | 3 | 2018-07-30 - 18:16 | almost 6 years |
7.0.1 | MIT | 3 | 2018-07-20 - 02:51 | almost 6 years |
7.0.0 | MIT | 3 | 2018-07-16 - 19:03 | almost 6 years |
6.0.23 | MIT | 2 | 2018-06-21 - 18:43 | almost 6 years |
6.0.22 | MIT | 2 | 2018-04-28 - 05:21 | about 6 years |
6.0.21 | MIT | 2 | 2018-03-22 - 18:39 | about 6 years |
6.0.20 | MIT | 2 | 2018-03-17 - 01:57 | about 6 years |
6.0.19 | MIT | 2 | 2018-02-17 - 22:32 | about 6 years |
6.0.18 | MIT | 2 | 2018-02-15 - 11:48 | about 6 years |
6.0.17 | MIT | 2 | 2018-02-01 - 19:56 | over 6 years |
6.0.16 | MIT | 2 | 2018-01-06 - 02:44 | over 6 years |
6.0.15 | MIT | 2 | 2018-01-02 - 01:19 | over 6 years |
6.0.14 | MIT | 2 | 2017-11-02 - 13:51 | over 6 years |
6.0.13 | MIT | 2 | 2017-10-04 - 14:09 | over 6 years |
6.0.12 | MIT | 2 | 2017-09-25 - 07:22 | over 6 years |
6.0.11 | MIT | 2 | 2017-09-06 - 06:00 | over 6 years |
6.0.10 | MIT | 2 | 2017-08-27 - 10:00 | over 6 years |
6.0.9 | MIT | 2 | 2017-08-11 - 20:57 | almost 7 years |
6.0.8 | MIT | 2 | 2017-07-19 - 16:01 | almost 7 years |
6.0.7 | MIT | 2 | 2017-07-17 - 15:16 | almost 7 years |
6.0.6 | MIT | 2 | 2017-07-05 - 16:33 | almost 7 years |
6.0.5 | MIT | 2 | 2017-07-03 - 11:18 | almost 7 years |
6.0.4 | MIT | 2 | 2017-06-30 - 11:39 | almost 7 years |
6.0.3 | MIT | 2 | 2017-06-23 - 19:17 | almost 7 years |
6.0.2 | MIT | 2 | 2017-06-12 - 18:47 | almost 7 years |
6.0.1 | MIT | 2 | 2017-05-07 - 11:37 | about 7 years |
6.0.0 | MIT | 2 | 2017-05-06 - 11:44 | about 7 years |
5.2.18 | MIT | 2 | 2017-10-04 - 13:48 | over 6 years |
5.2.17 | MIT | 2 | 2017-04-13 - 22:57 | about 7 years |
5.2.16 | MIT | 2 | 2017-03-07 - 15:51 | about 7 years |
5.2.15 | MIT | 2 | 2017-02-22 - 12:00 | about 7 years |
5.2.14 | MIT | 2 | 2017-02-17 - 09:03 | about 7 years |
5.2.13 | MIT | 2 | 2017-02-14 - 11:19 | about 7 years |
5.2.12 | MIT | 2 | 2017-02-05 - 21:32 | over 7 years |
5.2.11 | MIT | 2 | 2017-01-20 - 08:48 | over 7 years |
5.2.10 | MIT | 2 | 2017-01-12 - 07:51 | over 7 years |
5.2.9 | MIT | 2 | 2017-01-09 - 07:15 | over 7 years |
5.2.8 | MIT | 2 | 2016-12-26 - 08:08 | over 7 years |
5.2.7 | MIT | 2 | 2016-12-24 - 08:46 | over 7 years |
5.2.6 | MIT | 2 | 2016-11-22 - 12:55 | over 7 years |
5.2.5 | MIT | 2 | 2016-10-20 - 12:26 | over 7 years |
5.2.4 | MIT | 2 | 2016-09-30 - 05:20 | over 7 years |
5.2.3 | MIT | 2 | 2016-09-29 - 09:50 | over 7 years |
5.2.2 | MIT | 2 | 2016-09-26 - 12:58 | over 7 years |
5.2.1 | MIT | 2 | 2016-09-26 - 12:11 | over 7 years |
5.2.0 | MIT | 2 | 2016-09-07 - 04:29 | over 7 years |
5.1.2 | MIT | 2 | 2016-08-06 - 18:02 | almost 8 years |
5.1.1 | MIT | 2 | 2016-07-26 - 09:03 | almost 8 years |
5.1.0 | MIT | 2 | 2016-07-12 - 16:39 | almost 8 years |
5.0.21 | MIT | 2 | 2016-05-02 - 16:12 | about 8 years |
5.0.20 | MIT | 2 | 2016-05-01 - 06:09 | about 8 years |
5.0.19 | MIT | 2 | 2016-03-02 - 18:51 | about 8 years |
5.0.18 | MIT | 2 | 2016-02-29 - 08:33 | about 8 years |
5.0.17 | MIT | 2 | 2016-02-26 - 16:10 | about 8 years |
5.0.16 | MIT | 2 | 2016-02-14 - 08:54 | about 8 years |
5.0.15 | MIT | 2 | 2016-02-11 - 14:22 | about 8 years |
5.0.14 | MIT | 2 | 2016-01-03 - 21:47 | over 8 years |
5.0.13 | MIT | 2 | 2015-12-16 - 14:01 | over 8 years |
5.0.12 | MIT | 2 | 2015-11-13 - 15:27 | over 8 years |
5.0.11 | MIT | 2 | 2015-11-07 - 14:03 | over 8 years |
5.0.10 | MIT | 2 | 2015-10-14 - 23:46 | over 8 years |
5.0.9 | MIT | 2 | 2015-10-08 - 18:32 | over 8 years |
5.0.8 | MIT | 2 | 2015-09-25 - 11:16 | over 8 years |
5.0.7 | MIT | 2 | 2015-09-25 - 10:33 | over 8 years |
5.0.6 | MIT | 2 | 2015-09-21 - 16:42 | over 8 years |
5.0.5 | MIT | 2 | 2015-09-12 - 10:36 | over 8 years |
5.0.4 | MIT | 2 | 2015-09-01 - 18:24 | over 8 years |
5.0.3 | MIT | 2 | 2015-08-28 - 22:04 | over 8 years |
5.0.2 | MIT | 2 | 2015-08-22 - 14:25 | over 8 years |
5.0.1 | MIT | 2 | 2015-08-20 - 21:34 | over 8 years |
5.0.0 | MIT | 2 | 2015-08-19 - 19:11 | over 8 years |