Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29469

Опубликовано: 23 апр. 2021
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service. The issue is patched in version 3.1.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redis.js:redis:*:*:*:*:*:node.js:*:*
Версия до 3.1.1 (исключая)

EPSS

Процентиль: 70%
0.0062
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
NVD-CWE-Other

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service. The issue is patched in version 3.1.1.

CVSS3: 5.3
debian
почти 5 лет назад

Node-redis is a Node.js Redis client. Before version 3.1.1, when a cli ...

CVSS3: 7.5
github
почти 5 лет назад

Node-Redis potential exponential regex in monitor mode

EPSS

Процентиль: 70%
0.0062
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
NVD-CWE-Other