Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3749

Опубликовано: 31 авг. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

axios is vulnerable to Inefficient Regular Expression Complexity

A Regular Expression Denial of Service (ReDoS) vulnerability was found in the nodejs axios. This flaw allows an attacker to provide crafted input to the trim function, which might cause high resources consumption and as a consequence lead to denial of service. The highest threat from this vulnerability is system availability.

Отчет

  • OpenShift Container Platform (OCP) grafana-container does package a vulnerable version of nodejs axios. However, due to the instance being read only and behind OpenShift OAuth, the impact of this vulnerability is Low.
  • Red Hat Advanced Cluster Management for Kubernetes (RHACM) 2.1 and previous versions does contain a vulnerable version of nodejs axios, RHACM 2.2 on towards are not affected versions. For RHACM 2.1, due to the instance being read only and behind OAuth, the impact of this vulnerability is Low.
  • Because Service Telemetry Framework 1.2 will be retiring soon and the flaw's impact is lower, no update will be provided at this time for STF's service-telemetry-operator-container and smart-gateway-operator-container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1kialiOut of support scope
OpenShift Service Mesh 1servicemesh-grafanaOut of support scope
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-header-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-ui-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/kui-web-terminal-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-ui-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1999784nodejs-axios: Regular expression denial of service in trim function

EPSS

Процентиль: 95%
0.08515
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

axios is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
nvd
около 5 лет назад

axios is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
debian
около 5 лет назад

axios is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
github
около 5 лет назад

axios Inefficient Regular Expression Complexity vulnerability

EPSS

Процентиль: 95%
0.08515
Низкий

7.5 High

CVSS3

Уязвимость CVE-2021-3749