First published: Fri Feb 18 2022(Updated: )
A vulnerability was found in the glob-parent package. Affected versions of this package are vulnerable to Regular expression Denial of Service (ReDoS) attacks, affecting system availability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nodejs | <18-9020020230327152102.rhel9 | 18-9020020230327152102.rhel9 |
redhat/nodejs | <1:16.19.1-1.el9_2 | 1:16.19.1-1.el9_2 |
redhat/nodejs-nodemon | <0:2.0.20-3.el9_2 | 0:2.0.20-3.el9_2 |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el7 | 0:18.0.6-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el8 | 0:18.0.6-1.redhat_00001.1.el8 |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el9 | 0:18.0.6-1.redhat_00001.1.el9 |
redhat/rh-nodejs14-nodejs | <0:14.21.1-3.el7 | 0:14.21.1-3.el7 |
redhat/rh-nodejs14-nodejs-nodemon | <0:2.0.20-2.el7 | 0:2.0.20-2.el7 |
redhat/glob-parent | <6.0.1 | 6.0.1 |
Gulpjs Glob-parent | >=6.0.0<6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this vulnerability is CVE-2021-35065.
CVE-2021-35065 has a severity level of 7.5 (high).
The following software is affected by CVE-2021-35065: glob-parent package (version up to 6.0.1), nodejs package (version up to 18-9020020230327152102.rhel9 or 1:16.19.1-1.el9_2), nodejs-nodemon package (version up to 0:2.0.20-3.el9_2), rh-sso7-keycloak package (version up to 0:18.0.6-1.redhat_00001.1.el7, el8, or el9), rh-nodejs14-nodejs package (version up to 0:14.21.1-3.el7), and rh-nodejs14-nodejs-nodemon package (version up to 0:2.0.20-2.el7).
The recommended remedy for CVE-2021-35065 is to upgrade the affected software to the specific versions mentioned in the vulnerability details.
Yes, here are some references for CVE-2021-35065: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/208298), [IBM Support](https://www.ibm.com/support/pages/node/6557106), [CVE Details](https://www.cve.org/CVERecord?id=CVE-2021-35065), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-35065), [Snyk](https://security.snyk.io/vuln/SNYK-JS-GLOBPARENT-1314294).