First published: Fri Mar 12 2021(Updated: )
A flaw was found in ssri package. A malicious string provided by an attacker may lead to Regular Expression Denial of Service (ReDoS). This issue only affects consumers using the strict option. The highest threat from this vulnerability is to availability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/ssri | =8.0.0 | 8.0.1 |
npm/ssri | >=7.0.0<7.1.1 | 7.1.1 |
npm/ssri | >=5.2.2<6.0.2 | 6.0.2 |
redhat/rh-nodejs12-nodejs | <0:12.22.2-1.el7 | 0:12.22.2-1.el7 |
redhat/rh-nodejs12-nodejs-nodemon | <0:2.0.3-2.el7 | 0:2.0.3-2.el7 |
redhat/rh-nodejs14-nodejs | <0:14.17.2-1.el7 | 0:14.17.2-1.el7 |
redhat/rh-nodejs14-nodejs-nodemon | <0:2.0.3-2.el7 | 0:2.0.3-2.el7 |
Ssri Project Ssri | >=5.2.2<6.0.2 | |
Ssri Project Ssri | >=7.0.0<8.0.1 | |
Oracle GraalVM | =20.3.3 | |
Oracle GraalVM | =21.2.0 | |
Siemens Sinec Infrastructure Network Services | <1.0.1.1 | |
redhat/ssri | <8.0.1 | 8.0.1 |
redhat/ssri | <7.1.1 | 7.1.1 |
redhat/ssri | <6.0.2 | 6.0.2 |
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-27290 is a vulnerability in the ssri package that allows a denial of service attack by processing malicious strings that take a long time to process.
The ssri package versions 5.2.2-6.0.1 and 7.0.0-8.0.0 are affected by CVE-2021-27290.
The severity of CVE-2021-27290 is high, with a severity score of 7.5.
To fix CVE-2021-27290, upgrade to ssri version 8.0.1 if using npm or the corresponding version provided by Red Hat if using their package.
You can find more information about CVE-2021-27290 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-27290), [GitHub](https://github.com/npm/ssri/commit/76e223317d971f19e4db8191865bdad5edee40d2), [Doyensec Advisory](https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf).