Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23368

Опубликовано: 12 апр. 2021
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

A regular expression denial of service (ReDoS) vulnerability was found in the npm library postcss. When parsing a supplied CSS string, if it contains an unexpected value then as the supplied CSS grows in length it will take an ever increasing amount of time to process. An attacker can use this vulnerability to potentially craft a malicious a long CSS value to process resulting in a denial of service.

Отчет

In Red Hat OpenShift Container Platform (RHOCP), OpenShift ServiceMesh (OSSM) and Red Hat Advanced Cluster Management for Kubernetes (RHACM) the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-postcss library to authenticated users only, therefore the impact is low. Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-postcss library is used, but due to the code changing to the container first content the kibana package is marked as wontfix. This may be fixed in the future. In Red Had Quay , whilst a vulnerable version of postcss is included in the quay-rhel8 container it is a development dependency only, therefor the impact is low. In Red Hat Virtualization a vulnerable version of postcss is used in cockpit-ovirt, ovirt-web-ui and ovirt-engine-ui-extensions. However, it is only used during development and is used to process known CSS content. This flaw has been marked as "wontfix" and it may be addressed in future updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
Red Hat Advanced Cluster Management for Kubernetes 2application-uiFix deferred
Red Hat Advanced Cluster Management for Kubernetes 2consoleFix deferred
Red Hat Advanced Cluster Management for Kubernetes 2search-uiFix deferred
Red Hat Ansible Automation Platform 1.2postcssNot affected
Red Hat OpenShift Container Platform 3.11kibanaNot affected
Red Hat OpenShift Container Platform 4golang-github-prometheus-prometheusFix deferred
Red Hat OpenShift Container Platform 4kibanaWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1948763nodejs-postcss: Regular expression denial of service during source map parsing

EPSS

Процентиль: 53%
0.003
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

CVSS3: 5.3
nvd
почти 5 лет назад

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

CVSS3: 5.3
debian
почти 5 лет назад

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Reg ...

CVSS3: 5.3
github
больше 4 лет назад

Regular Expression Denial of Service in postcss

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость библиотеки PostCSS прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 53%
0.003
Низкий

5.3 Medium

CVSS3