First published: Fri May 21 2021(Updated: )
A flaw was found in normalize-url. Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/normalize-url | >=4.3.0<4.5.1 | 4.5.1 |
npm/normalize-url | >=6.0.0<6.0.1 | 6.0.1 |
npm/normalize-url | >=5.0.0<5.3.1 | 5.3.1 |
IBM Sterling External Authentication Server | <=6.1.0 | |
Normalize-url Project Normalize-url | >=4.3.0<4.5.1 | |
Normalize-url Project Normalize-url | >=5.0.0<5.3.1 | |
Normalize-url Project Normalize-url | =6.0.0 | |
redhat/nodejs-nodemon | <0:2.0.19-1.el9_0 | 0:2.0.19-1.el9_0 |
redhat/rh-nodejs12-nodejs | <0:12.22.2-1.el7 | 0:12.22.2-1.el7 |
redhat/rh-nodejs12-nodejs-nodemon | <0:2.0.3-2.el7 | 0:2.0.3-2.el7 |
redhat/rh-nodejs14-nodejs | <0:14.17.2-1.el7 | 0:14.17.2-1.el7 |
redhat/rh-nodejs14-nodejs-nodemon | <0:2.0.3-2.el7 | 0:2.0.3-2.el7 |
redhat/ovirt-engine-ui-extensions | <0:1.3.3-1.el8e | 0:1.3.3-1.el8e |
redhat/ovirt-web-ui | <0:1.8.1-2.el8e | 0:1.8.1-2.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-33502 is a vulnerability in the normalize-url module in Node.js that allows for a denial of service attack.
CVE-2021-33502 is classified as a high severity vulnerability with a severity rating of 7.5.
CVE-2021-33502 impacts normalize-url by causing a denial of service condition.
To fix CVE-2021-33502, update normalize-url to version 4.5.1 or higher.
You can find more information about CVE-2021-33502 on the NVD website.