Описание
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.
A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invoked, leading to excessive CPU consumption. This can result in a Denial of Service (DoS) for the affected system.
Отчет
This is an Important denial of service vulnerability in the linkify-it library. Systems processing untrusted user-supplied text containing specially crafted mailto: links may experience excessive CPU consumption due to a quadratic complexity issue in the mailto: schema validator, leading to temporary service disruption.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | Under investigation | ||
| Node HealthCheck Operator | workload-availability/node-healthcheck-must-gather-rhel9 | Under investigation | ||
| Node HealthCheck Operator | workload-availability/node-healthcheck-operator-bundle | Under investigation | ||
| Node HealthCheck Operator | workload-availability/node-healthcheck-rhel9-operator | Under investigation | ||
| Node HealthCheck Operator | workload-availability/node-remediation-console-rhel8 | Under investigation | ||
| Node HealthCheck Operator | workload-availability/node-remediation-console-rhel9 | Under investigation | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-pf5-rhel9 | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel9 | Affected | ||
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Not affected | ||
| Red Hat Ceph Storage 9 | thrift | Under investigation |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
EPSS
7.5 High
CVSS3