Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25883

Опубликовано: 21 июн. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in node-semver package via the 'new Range' function. This issue could allow an attacker to pass untrusted malicious regex user data as a range, causing the service to excessively consume CPU depending upon the input size, resulting in a denial of service.

Отчет

This vulnerability is rated Moderate for Red Hat Products versus NVD's High due to deployment context. The flaw in node-semver's new Range() function causes catastrophic regex backtracking on crafted input, leading to CPU exhaustion. However, exploitation requires untrusted input passed directly to the parser. So node-semver is a build-time dev dependency, not present in runtime environment in RHACM, and the functionality is additionally protected behind OAuth authentication, further limiting attack surface.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2nodejs-semverNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Migration Toolkit for Applications 6mta/mta-ui-rhel9Will not fix
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Affected
OpenShift Serverlessnodejs-semverAffected
OpenShift Service Mesh 2openshift-service-mesh/kiali-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2acm-cluster-templates-console-plugin-containerFix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-api-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2216475nodejs-semver: Regular expression denial of service

EPSS

Процентиль: 69%
0.00581
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 3 года назад

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

CVSS3: 5.3
nvd
почти 3 года назад

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

msrc
около 1 месяца назад

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range when untrusted user data is provided as a range.

CVSS3: 5.3
debian
почти 3 года назад

Versions of the package semver before 7.5.2 are vulnerable to Regular ...

CVSS3: 7.5
github
почти 3 года назад

semver vulnerable to Regular Expression Denial of Service

EPSS

Процентиль: 69%
0.00581
Низкий

7.5 High

CVSS3