CVE-2021-33502: High severity IBM Sterling External Authentication Server vulnerability
A flaw was found in normalize-url. Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data.
Other sources
Node.js normalize-url module is vulnerable to a denial of service, caused by a ReDoS (regular expression denial of service) flaw in the data URLs. By using a specially-crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-33502?
CVE-2021-33502 is a vulnerability in the normalize-url module in Node.js that allows for a denial of service attack.
What is the severity of CVE-2021-33502?
CVE-2021-33502 is classified as a high severity vulnerability with a severity rating of 7.5.
How does CVE-2021-33502 impact normalize-url?
CVE-2021-33502 impacts normalize-url by causing a denial of service condition.
How can CVE-2021-33502 be fixed?
To fix CVE-2021-33502, update normalize-url to version 4.5.1 or higher.
Where can I find more information about CVE-2021-33502?
You can find more information about CVE-2021-33502 on the NVD website.