Описание
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
A flaw was found in nodejs-lodash. A Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions is possible.
Отчет
In OpenShift ServiceMesh (OSSM) and Red Hat OpenShift Jaeger (RHOSJ) the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low. While Red Hat Virtualization's cockpit-ovirt has a dependency on lodash it doesn't use the vulnerable toNumber, trim, or trimEnd functions. While Red Hat Quay has a dependency on lodash via restangular it doesn't use the vulnerable toNumber, trim, or trimEnd functions.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Service Mesh 2.0 | kiali | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | console-api | Affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | console-header | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | console-ui | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | grc-ui | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | grc-ui-api | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | kui-web-terminal | Affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | mcm-topology | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression ...
Regular Expression Denial of Service (ReDoS) in lodash
Уязвимость функций toNumber, trim и trimEnd библиотеки lodash прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3