Описание
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
Отчет
This issue affects the versions of rh-nodejs4-nodejs-debug, rh-nodejs6-nodejs-debug, and rh-nodejs8-nodejs-debug as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Red Hat Virtualization 4.2 EUS includes a vulnerable version of nodejs-debug as a part of the ovirt-engine-api-explorer package. This package is removed in Red Hat Virtualization 4.3. Red Hat Quay includes the debug library as a dependency of karma-webpack. It is only used at build time, and not runtime so its impact is reduce to low in Red Hat Quay.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Mobile Application Platform 4 | rhmap45/fh-aaa | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-appstore-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-mbaas-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-messaging-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-metrics-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-ngui-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-scm-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-statsd-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-supercore-docker | Not affected | ||
| Red Hat OpenShift Enterprise 3 | nodejs-debug | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
The debug module is vulnerable to regular expression denial of service ...
Уязвимость библиотеки debug прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3