Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7754

Опубликовано: 16 окт. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

Отчет

In Red Hat Enterprise Linux 8 and Software Collections, npm-user-validate is used exclusively for npm. As a result, this vulnerability is considered Low in such a context. In OpenShift Container Platform (OCP) 3.11 and 4.4 the kibana package has been marked Low (similar to RHEL8) as it is primarily used for npm and is protected via OpenShift OAuth. Additionally, whilst OCP 4.4 does deliver the kibana package, due to the code changing to container first content, it has been marked as wontfix at this time and may be fixed in a future release. Additionally, the openshift4/ose-logging-kibana6 container is not represented on the CVE page as it gets npm from the Red Hat Software Collections and as such the ose-logging-kibana6 container will be updated when the rh-nodejs10-nodejs package is.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11kibanaFix deferred
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:054816.02.2021
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:054916.02.2021
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:055116.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs14-nodejsFixedRHSA-2021:042104.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejsFixedRHSA-2021:048511.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejs-nodemonFixedRHSA-2021:048511.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs10-nodejsFixedRHSA-2021:052115.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-nodejs14-nodejsFixedRHSA-2021:042104.02.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1892430nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS

EPSS

Процентиль: 81%
0.0163
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

CVSS3: 7.5
github
около 4 лет назад

Regular expression denial of service in npm-user-validate

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость пакета npm-user-validate програмной платформы node.js, позволяющая нарушителю вызвать отказ в обслуживании

oracle-oval
больше 4 лет назад

ELSA-2021-0549: nodejs:12 security update (MODERATE)

rocky
больше 4 лет назад

Moderate: nodejs:14 security and bug fix update

EPSS

Процентиль: 81%
0.0163
Низкий

7.5 High

CVSS3