Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28092

Опубликовано: 11 мар. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.

A flaw was found in is-svg package. A malicious string provided by an attacker may lead to Regular Expression Denial of Service (ReDoS). The highest threat from this vulnerability is to availability.

Отчет

Red Hat OpenShift Container Platform (RHOCP) 4 delivers the kibana package where the nodejs-is-svg package is bundled, but during the update to container first (to openshift4/ose-logging-kibana6 since OCP 4.5) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future. In OpenShift ServiceMesh (OSSM) and Red Hat OpenShift Container Platform (RHOCP) the affected components are behind OpenShift OAuth. This restricts access to the vulnerable nodejs-is-svg to authenticated users only, therefore the impact is low. Red Hat Quay includes is-svg as a dependency of css-loader which is only using during development, not runtime. This issues has been rated low impact for Red Hat Quay.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-ui-rhel8Affected
Red Hat OpenShift Container Platform 3.11kibanaFix deferred
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaFix deferred
Red Hat Quay 3quay/quay-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2acmesolver-containerFixedRHSA-2021:149904.05.2021
Red Hat Advanced Cluster Management for Kubernetes 2acm-must-gather-containerFixedRHSA-2021:149904.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1939103nodejs-is-svg: ReDoS via malicious string

EPSS

Процентиль: 73%
0.00741
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.

CVSS3: 7.5
github
почти 5 лет назад

Regular Expression Denial of Service (ReDoS)

EPSS

Процентиль: 73%
0.00741
Низкий

7.5 High

CVSS3