{"id":"GHSA-h96f-fc7c-9r55","aliases":[],"url":"https://o3.security/vulnerability/GHSA-h96f-fc7c-9r55","summary":"Regex denial of service vulnerability in codesample plugin","details":"### Impact\nA regex denial of service (ReDoS) vulnerability was discovered in a dependency of the `codesample` plugin. The vulnerability allowed poorly formed ruby code samples to lock up the browser while performing syntax highlighting. This impacts users of the `codesample` plugin using TinyMCE 5.5.1 or lower.\n\n### Patches\nThis vulnerability has been patched in TinyMCE 5.6.0 by upgrading to a version of the dependency without the vulnerability.\n\n### Workarounds\nTo work around this vulnerability, either:\n- Upgrade to TinyMCE 5.6.0 or higher\n- Disable the `codesample` plugin\n- Disable ruby code samples using the [codesample_languages](https://www.tiny.cloud/docs/plugins/opensource/codesample/#exampleusingcodesample_languages) setting\n- Override the PrismJS syntax highlighter to version 1.21.0 or higher using the [codesample_global_prismjs](https://www.tiny.cloud/docs/plugins/opensource/codesample/#codesample_global_prismjs) setting\n\n### Acknowledgements\nTiny Technologies would like to thank Erik Krogh Kristensen at GitHub for discovering this vulnerability.\n\n### References\nhttps://www.tiny.cloud/docs/release-notes/release-notes56/#securityfixes\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in the [TinyMCE repo](http://github.com/tinymce/tinymce/issues)\n* Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud)","published":"2021-01-06T19:25:46Z","modified":"2021-01-06T19:25:24Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"tinymce","fixedVersion":"5.6.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/tinymce/tinymce/security/advisories/GHSA-h96f-fc7c-9r55"},{"type":"WEB","url":"https://www.npmjs.com/package/tinymce"},{"type":"WEB","url":"https://www.tiny.cloud/docs/release-notes/release-notes56/#securityfixes"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-01-06T19:25:24Z"}}