Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3801

Опубликовано: 11 сент. 2021
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

prism is vulnerable to Inefficient Regular Expression Complexity

Insufficient Regular Expression Complexity in prismjs leads to a Regular Expression Denial of Service (ReDoS) attack. An unauthenticated attacker can exploit this flaw to cause an application to consume an excess amount of CPU by providing a crafted HTML comment as input. This can result in a denial of service attack.

Отчет

OpenShift Container Platform (OCP) grafana-container does package a vulnerable verison of prismjs. However due to the instance being read only and behind OpenShift OAuth, it has been given a Low impact. Additionally it has been marked as wont-fix at this time and may be fixed in a future release. Just as OCP, OpenShift ServiceMesh (OSSM) components are behind OpenShift OAuth what reducing impact to Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Fix deferred
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
Red Hat Ceph Storage 3grafanaOut of support scope
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaWill not fix
Red Hat Storage 3grafanaAffected
RHACS-3.67-RHEL-8advanced-cluster-security/rhacs-rhel8-operatorFixedRHSA-2021:490201.12.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2005445nodejs-prismjs: ReDoS vulnerability

EPSS

Процентиль: 51%
0.0028
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

prism is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 6.5
nvd
больше 4 лет назад

prism is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 6.5
debian
больше 4 лет назад

prism is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 6.5
github
больше 4 лет назад

prismjs Regular Expression Denial of Service vulnerability

EPSS

Процентиль: 51%
0.0028
Низкий

6.5 Medium

CVSS3