Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23424

Опубликовано: 07 мая 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.

Отчет

In OpenShift Service Mesh, as the prometheus interface is behind authentication, the impact of has been lowered. In Red Hat Advanced Management for Kubernetes (RHACM) is protected behind OAuth so the impact has been set to low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-prometheusOut of support scope
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/kui-web-terminal-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-ui-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1995798nodejs-ansi-html: ReDoS via crafted string

EPSS

Процентиль: 42%
0.00204
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.

CVSS3: 7.5
github
больше 4 лет назад

Uncontrolled Resource Consumption in ansi-html

EPSS

Процентиль: 42%
0.00204
Низкий

7.5 High

CVSS3