Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3807

Опубликовано: 17 сент. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

A regular expression denial of service (ReDoS) vulnerability was found in nodejs-ansi-regex. This could possibly cause an application using ansi-regex to use an excessive amount of CPU time when matching crafted ANSI escape codes.

Отчет

This flaw requires crafted invalid ANSI escape codes in order to be exploited and only allows for denial of service of applications on the client side, hence the impact has been rated as Moderate. In Red Hat Virtualization and Red Hat Quay some components use a vulnerable version of ansi-regex. However, all frontend code is executed on the client side. As the maximum impact of this vulnerability is denial of service in the client, the vulnerability is rated Moderate for those products. OpenShift Container Platform 4 (OCP) ships affected version of ansi-regex in the ose-metering-hadoop container, however the metering operator is deprecated since 4.6[1]. This issue is not currently planned to be addressed in future updates and hence hadoop container has been marked as 'will not fix'. Advanced Cluster Management for Kubernetes (RHACM) ships the affected version of ansi-regex in several containers, however the impact of this vulnerability is deemed low as it would result in an authenticated slowing down their own user interface. [1] https://docs.openshift.com/container-platform/4.6/metering/metering-about-metering.html

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Fix deferred
OpenShift Service Mesh 1kialiOut of support scope
OpenShift Service Mesh 1servicemesh-grafanaOut of support scope
OpenShift Service Mesh 1servicemesh-prometheusOut of support scope
OpenShift Service Mesh 2.0servicemesh-grafanaWill not fix
OpenShift Service Mesh 2.0servicemesh-prometheusWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-api-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-header-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2007557nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes

EPSS

Процентиль: 44%
0.00215
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
nvd
почти 4 года назад

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
debian
почти 4 года назад

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
github
больше 3 лет назад

Inefficient Regular Expression Complexity in chalk/ansi-regex

CVSS3: 7.5
fstec
почти 4 года назад

Уязвимость библиотеки сравнения с регулярными выражениями ANSI escape-кодов Ansi-regex, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 44%
0.00215
Низкий

7.5 High

CVSS3