Описание
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
The mime module is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
Отчет
Red Hat Virtualization 4.2 EUS contained a vulnerable version of nodejs-mime in the ovirt-engine-dashboard package. This package has been removed in Red Hat Virtualization 4.2. Red Hat Quay includes mime as a dependency of Karma. It's only used at build time, not runtime so this vulnerability has a low impact of Red Hat Quay.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Mobile Application Platform 4 | rhmap45/fh-aaa | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-appstore-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-mbaas-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-messaging-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-metrics-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-ngui-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-scm-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-statsd-docker | Not affected | ||
| Red Hat Mobile Application Platform 4 | rhmap-fh-supercore-docker | Not affected | ||
| Red Hat OpenShift Enterprise 3 | nodejs-mime | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular express ...
mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input
EPSS
5.3 Medium
CVSS3