Описание
semver-regex is vulnerable to Inefficient Regular Expression Complexity
A flaw was found in the semver-regex library where it could lead to consuming a big amount of resources when executing specific strings. Attackers could take advantage of this by crafting an invalid version causing a disruption or a denial of service (DoS).
Отчет
The Red Hat Directory Server 11 Web UI semver-regex as a dependency, but it is not used in the 389-ds cockpit plugin, and not shipped as part of the RPM binary. Thus Red Hat Directory Server 11 is not affected by this flaw. In Red Hat Virtualization semver-regex is a dependency of semantic-release, which is used for release automation. The vulnerability may cause a denial of service during the release process of the components using the semantic-release package, and not their functionality. As such, the impact of this vulnerability for Red Hat Virtualization is rated Low and will not be addressed immediately. Future releases may include fixes. In Red Hat Advanced Cluster Management for Kubernetes (RHACM) the server-regexp dependency is protected by OAuth what is reducing impact by this flaw to Low.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-api-rhel8 | Fix deferred | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Fix deferred | ||
| Red Hat Directory Server 11 | redhat-ds:11/389-ds-base | Not affected | ||
| Red Hat Virtualization 4 | ovirt-engine-ui-extensions | Will not fix | ||
| Red Hat Virtualization 4 | ovirt-web-ui | Will not fix | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | acmesolver-container | Fixed | RHSA-2021:3873 | 14.10.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | acm-must-gather-container | Fixed | RHSA-2021:3873 | 14.10.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | acm-operator-bundle-container | Fixed | RHSA-2021:3873 | 14.10.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | application-ui-container | Fixed | RHSA-2021:3873 | 14.10.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | cainjector-container | Fixed | RHSA-2021:3873 | 14.10.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
semver-regex is vulnerable to Inefficient Regular Expression Complexity
semver-regex Regular Expression Denial of Service (ReDOS)
EPSS
7.5 High
CVSS3