Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7793

Опубликовано: 29 окт. 2020
Источник: redhat
CVSS3: 7.5

Описание

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

A flaw was found in nodejs-ua-parser-js. The software is vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes.

Отчет

Red Hat OpenShift Container Platform 4 delivers the kibana package where the ua-parser-js library is bundled, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future. Red Hat Ceph Storage 3 and 4 ship a version of grafana that pulls a version of ua-parser-js (0.7.9) that uses the affected code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Distributed Tracing Jaeger 1distributed-tracing/jaeger-all-in-one-rhel7Out of support scope
Distributed Tracing Jaeger 1distributed-tracing/jaeger-query-rhel7Out of support scope
OpenShift Service Mesh 1servicemesh-grafanaNot affected
Red Hat Advanced Cluster Management for Kubernetes 2nodejs-ua-parser-jsFix deferred
Red Hat Ceph Storage 3grafanaAffected
Red Hat Ceph Storage 3grafana-containerAffected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat OpenShift Container Platform 3.11kibanaFix deferred
Red Hat OpenShift Container Platform 3.11openshift3/grafanaNot affected
Red Hat OpenShift Container Platform 4kibanaWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1907451nodejs-ua-parser-js: ReDoS in multiple regexes

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

CVSS3: 7.5
nvd
около 5 лет назад

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

CVSS3: 7.5
debian
около 5 лет назад

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expre ...

CVSS3: 7.5
github
почти 4 года назад

ua-parser-js Regular Expression Denial of Service vulnerability

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость библиотеки ua-parser-js прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3