Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25887

Опубликовано: 30 авг. 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

A flaw was found in sanitize-html library. Insecure global regular expression replacement logic of HTML comment removal could lead to a regular expression Denial of Service (ReDoS), affecting the availability of the affected component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
OpenShift Service Mesh 2.1servicemesh-prometheusFix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected
Red Hat Ansible Automation Platform 2automation-controllerAffected
Red Hat OpenShift Container Platform 3.11openshift3/ose-consoleAffected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleAffected
Red Hat OpenShift Dev Spacesdevspaces/dashboard-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2acm-governance-policy-addon-controller-containerFixedRHSA-2022:731302.11.2022
Red Hat Advanced Cluster Management for Kubernetes 2acm-grafana-containerFixedRHSA-2022:731302.11.2022
Red Hat Advanced Cluster Management for Kubernetes 2acm-must-gather-containerFixedRHSA-2022:731302.11.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-185
https://bugzilla.redhat.com/show_bug.cgi?id=2123376sanitize-html: insecure global regular expression replacement logic may lead to ReDoS

EPSS

Процентиль: 46%
0.00231
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

CVSS3: 5.3
nvd
больше 3 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

CVSS3: 5.3
debian
больше 3 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expre ...

CVSS3: 7.5
github
больше 3 лет назад

Sanitize-html Vulnerable To REDoS Attacks

EPSS

Процентиль: 46%
0.00231
Низкий

5.3 Medium

CVSS3