Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-21538

Опубликовано: 08 нояб. 2024
Источник: redhat
CVSS3: 4.4

Описание

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

A Regular Expression Denial of Service (ReDoS) vulnerability was found in the cross-spawn package for Node.js. Due to improper input sanitization, an attacker can increase CPU usage and crash the program with a large, specially crafted string.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3cross-spawnAffected
Migration Toolkit for Applications 7mta/mta-cli-rhel9Not affected
Migration Toolkit for Applications 7mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/multicluster-engine-console-mce-rhel8Not affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-console-plugin-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2324550cross-spawn: regular expression denial of service

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

CVSS3: 7.5
msrc
больше 1 года назад

Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization.

suse-cvrf
больше 1 года назад

Security update for nodejs18

suse-cvrf
больше 1 года назад

Security update for nodejs20

suse-cvrf
больше 1 года назад

Security update for nodejs20

4.4 Medium

CVSS3