Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23346

Опубликовано: 01 мар. 2021
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.

The html-parse-stringify library, as well as its fork html-parse-stringify2, are vulnerable to a Regular Expression Denial of Service attack (ReDos). A certain inputs could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.

Отчет

The access to the vulnerable library is protected by RHACM Authentication reducing impact of this flaw to LOW.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8rhacm2/search-ui-rhel8FixedRHSA-2021:301606.08.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1941675html-parse-stringify: Regular Expression DoS

EPSS

Процентиль: 53%
0.00301
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
почти 5 лет назад

This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.

CVSS3: 5.3
github
почти 5 лет назад

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

EPSS

Процентиль: 53%
0.00301
Низкий

5.3 Medium

CVSS3