Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-21222

Опубликовано: 30 сент. 2022
Источник: redhat
CVSS3: 7.5

Описание

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

A vulnerability was found in the css-what package. The flaw allows Regular expression denial of service (ReDoS) attacks, affecting system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Not affected
Migration Toolkit for Runtimescss-whatNot affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Not affected
OpenShift Developer Tools and ServicesodoNot affected
OpenShift Service Mesh 2openshift-service-mesh/kiali-rhel8Not affected
OpenShift Service Mesh 2.0openshift-service-mesh/kiali-rhel8Not affected
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusNot affected
OpenShift Service Mesh 2.1openshift-service-mesh/kiali-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2131335css-what: ReDoS due to insecure regular expression

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

CVSS3: 5.3
nvd
больше 3 лет назад

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

CVSS3: 5.3
debian
больше 3 лет назад

The package css-what before 2.1.3 are vulnerable to Regular Expression ...

CVSS3: 7.5
github
больше 3 лет назад

css-what vulnerable to ReDoS due to use of insecure regular expression

7.5 High

CVSS3