
Cloud Vulnerability DB
A community-led vulnerabilities database
A regex denial of service (ReDoS) vulnerability was discovered in a dependency of the codesample plugin in TinyMCE, identified as GHSA-h96f-fc7c-9r55. The vulnerability was discovered by Erik Krogh Kristensen at GitHub and affects TinyMCE versions below 5.6.0. The issue was published on January 6, 2021, and has been assigned a low severity rating (GitHub Advisory).
The vulnerability allowed poorly formed ruby code samples to lock up the browser while performing syntax highlighting. This affects users of the codesample plugin using TinyMCE 5.5.1 or lower. The issue has been classified as CWE-400 (Uncontrolled Resource Consumption) (GitHub Advisory).
When exploited, this vulnerability could cause the browser to become unresponsive while processing syntax highlighting for malformed ruby code samples, potentially leading to a denial of service condition (GitHub Advisory).
The vulnerability specifically affects the syntax highlighting functionality when processing ruby code samples in the codesample plugin. The issue can be triggered by submitting malformed ruby code through the plugin (GitHub Advisory).
Several mitigation options are available: upgrade to TinyMCE 5.6.0 or higher, disable the codesample plugin, disable ruby code samples using the codesample_languages setting, or override the PrismJS syntax highlighter to version 1.21.0 or higher using the codesample_global_prismjs setting. The vulnerability has been patched in TinyMCE 5.6.0 by upgrading to a version of the dependency without the vulnerability (Tiny Docs, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."