Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35q2-47q7-3pc3

Опубликовано: 27 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Node-Redis potential exponential regex in monitor mode

Impact

When a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service.

Patches

The problem was fixed in commit 2d11b6d and was released in version 3.1.1.

References

#1569 (GHSL-2021-026)

Пакеты

Наименование

redis

npm
Затронутые версииВерсия исправления

>= 2.6.0, < 3.1.1

3.1.1

EPSS

Процентиль: 70%
0.0062
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service. The issue is patched in version 3.1.1.

CVSS3: 5.3
nvd
почти 5 лет назад

Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service. The issue is patched in version 3.1.1.

CVSS3: 5.3
debian
почти 5 лет назад

Node-redis is a Node.js Redis client. Before version 3.1.1, when a cli ...

EPSS

Процентиль: 70%
0.0062
Низкий

7.5 High

CVSS3

Дефекты

CWE-400