Описание
All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
A flaw was found in the scss-tokenizer package. Affected versions of this package are vulnerable to a regular expression denial of service (ReDoS) attacks.
Отчет
In OpenShift Service Mesh (OSSM) the vulnerable scss-tokenizer nodejs package is shipped in openshift-service-mesh/kiali-rhel8 and openshift-service-mesh/grafana-rhel8 container images. In the openshift-service-mesh/grafana-rhel8, the scss-tokenizer nodejs package is shipped as a part of the grafana rpm package, which is consumed from Red Hat Enterprise Linux (RHEL) repositories starting from OSSM 2.0.9 version. Once this vulnerability will be fixed in RHEL product, fixed version of grafana package will be consumed by OSSM and delivered in the next OSSM releases. In older versions than OSSM 2.0.9 the openshift-service-mesh/grafana-rhel8 container contains servicemesh-grafana rpm package from OSSM repositories and these versions are not supported anymore, hence the servicemesh-grafana rpm package is listed as affected with "Will not fix" state. In OSSM openshift-service-mesh/kiali-rhel8 container image, the scss-tokenizer nodejs package is only listed as a development dependency, without impact to the runtime environment, hence is marked as "Will not fix".
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Will not fix | ||
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Will not fix | ||
| OpenShift Service Mesh 2.1 | openshift-service-mesh/kiali-rhel8 | Will not fix | ||
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/application-ui-rhel8 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-rhel8 | Not affected | ||
| Red Hat Ceph Storage 4 | cockpit-ceph-installer | Affected | ||
| Red Hat Decision Manager 7 | scss-tokenizer | Out of support scope | ||
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Will not fix | ||
| Red Hat Enterprise Linux 8 | cockpit-podman | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
All versions of package scss-tokenizer are vulnerable to Regular Expre ...
Regular expression denial of service in scss-tokenizer
EPSS
5.3 Medium
CVSS3