Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23425

Опубликовано: 26 мая 2021
Источник: redhat
CVSS3: 5.3

Описание

All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.

A flaw was found in nodejs-trim-off-newlines. All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing. The highest threat from this vulnerability is to system availability.

Отчет

The Red Hat Directory Server 11 Web UI requires trim-off-newlines as a dependency, but it is not used in the 389-ds cockpit plugin, and not shipped as part of the RPM binary. Thus Red Hat Directory Server 11 is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseNot affected
Red Hat Virtualization 4ovirt-web-uiNot affected
Red Hat Virtualization Engine 4.4ovirt-engine-ui-extensionsFixedRHSA-2022:471126.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1995793nodejs-trim-off-newlines: ReDoS via string processing

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.

CVSS3: 5.3
github
больше 4 лет назад

Uncontrolled Resource Consumption in trim-off-newlines

5.3 Medium

CVSS3