Description
MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0554 | MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue. |
Github GHSA |
GHSA-v63q-hgqc-qvpg | MooTools Regular Expression Denial of Service |
References
History
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:33:30.800Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32821
Updated: 2024-08-03T23:33:55.864Z
Status : Modified
Published: 2023-01-03T17:15:10.210
Modified: 2024-11-21T06:07:49.157
Link: CVE-2021-32821
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA