Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23382

Опубликовано: 26 апр. 2021
Источник: redhat
CVSS3: 5.3

Описание

The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern /*\s* sourceMappingURL=(.*).

A regular expression denial of service (ReDoS) vulnerability was found in the npm library postcss when using getAnnotationURL() or loadAnnotation() options in lib/previous-map.js. An attacker can use this vulnerability to potentially craft a malicious CSS to process resulting in a denial of service.

Отчет

In Red Hat OpenShift Container Platform (RHOCP), OpenShift ServiceMesh (OSSM) and Red Hat Advanced Cluster Management for Kubernetes (RHACM) the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-postcss library to authenticated users only, therefore the impact is low. Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-postcss library is used, but due to the code changing to the container first content the kibana package is marked as wontfix. This may be fixed in the future. In Red Had Quay , whilst a vulnerable version of postcss is included in the quay-rhel8 container it is a development dependency only, therefor the impact is low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
Red Hat Advanced Cluster Management for Kubernetes 2application-uiFix deferred
Red Hat Advanced Cluster Management for Kubernetes 2console-headerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2console-uiNot affected
Red Hat Advanced Cluster Management for Kubernetes 2mcm-topologyNot affected
Red Hat Advanced Cluster Management for Kubernetes 2search-uiFix deferred
Red Hat Ansible Automation Platform 1.2postcssNot affected
Red Hat OpenShift Container Platform 3.11kibanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1954150nodejs-postcss: ReDoS via getAnnotationURL() and loadAnnotation() in lib/previous-map.js

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).

CVSS3: 5.3
nvd
почти 5 лет назад

The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).

CVSS3: 5.3
debian
почти 5 лет назад

The package postcss before 8.2.13 are vulnerable to Regular Expression ...

CVSS3: 5.3
github
около 4 лет назад

Regular Expression Denial of Service in postcss

5.3 Medium

CVSS3