CVE-2021-3649: Inefficient Regular Expression Complexity in chatwoot/chatwoot
Published Jul 16, 2021
·Updated
chatwoot is vulnerable to Inefficient Regular Expression Complexity
Affected Software
1 affected component
chatwoot Chatwoot<1.18.0
Remediation
Patch Available
Event History
Jul 16, 2021
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-3649?
CVE-2021-3649 has been classified with a high severity due to its potential impact on system performance and security.
2
How do I fix CVE-2021-3649?
To fix CVE-2021-3649, update your Chatwoot installation to version 1.18.0 or later.
3
What impact does CVE-2021-3649 have on Chatwoot?
CVE-2021-3649 can lead to denial of service due to inefficient regular expression processing, impacting system responsiveness.
4
Is CVE-2021-3649 a remote code execution vulnerability?
No, CVE-2021-3649 is not classified as a remote code execution vulnerability but rather affects performance through inefficient regex.
5
What software versions are affected by CVE-2021-3649?
CVE-2021-3649 affects all versions of Chatwoot up to but not including 1.18.0.