Описание
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
A regular expression denial of service (ReDoS) vulnerability was found in nodejs-ansi-regex. This could possibly cause an application using ansi-regex to use an excessive amount of CPU time when matching crafted ANSI escape codes.
Отчет
This flaw requires crafted invalid ANSI escape codes in order to be exploited and only allows for denial of service of applications on the client side, hence the impact has been rated as Moderate. In Red Hat Virtualization and Red Hat Quay some components use a vulnerable version of ansi-regex. However, all frontend code is executed on the client side. As the maximum impact of this vulnerability is denial of service in the client, the vulnerability is rated Moderate for those products. OpenShift Container Platform 4 (OCP) ships affected version of ansi-regex in the ose-metering-hadoop container, however the metering operator is deprecated since 4.6[1]. This issue is not currently planned to be addressed in future updates and hence hadoop container has been marked as 'will not fix'. Advanced Cluster Management for Kubernetes (RHACM) ships the affected version of ansi-regex in several containers, however the impact of this vulnerability is deemed low as it would result in an authenticated slowing down their own user interface. [1] https://docs.openshift.com/container-platform/4.6/metering/metering-about-metering.html
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-ui-rhel8 | Fix deferred | ||
OpenShift Service Mesh 1 | kiali | Out of support scope | ||
OpenShift Service Mesh 1 | servicemesh-grafana | Out of support scope | ||
OpenShift Service Mesh 1 | servicemesh-prometheus | Out of support scope | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Will not fix | ||
OpenShift Service Mesh 2.0 | servicemesh-prometheus | Will not fix | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/application-ui-rhel8 | Affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-api-rhel8 | Affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-header-rhel8 | Fix deferred | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
Inefficient Regular Expression Complexity in chalk/ansi-regex
Уязвимость библиотеки сравнения с регулярными выражениями ANSI escape-кодов Ansi-regex, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3