ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ssri | Ssri_project | 5.2.2 (including) | 6.0.2 (excluding) |
Ssri | Ssri_project | 7.0.0 (including) | 8.0.1 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | nodejs:12-8040020210708131418.522a0ee4 | * |
Red Hat Enterprise Linux 8 | RedHat | nodejs:14-8040020210708154809.522a0ee4 | * |
Red Hat Enterprise Linux 8.1 Extended Update Support | RedHat | nodejs:12-8010020210817113128.c27ad7f8 | * |
Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | nodejs:12-8020020210817125332.4cda2c84 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-nodejs12-nodejs-0:12.22.2-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-nodejs12-nodejs-nodemon-0:2.0.3-2.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-nodejs14-nodejs-0:14.17.2-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-nodejs14-nodejs-nodemon-0:2.0.3-2.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | RedHat | rh-nodejs12-nodejs-0:12.22.2-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | RedHat | rh-nodejs12-nodejs-nodemon-0:2.0.3-2.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | RedHat | rh-nodejs14-nodejs-0:14.17.2-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | RedHat | rh-nodejs14-nodejs-nodemon-0:2.0.3-2.el7 | * |
Node-ssri | Ubuntu | esm-apps/focal | * |
Node-ssri | Ubuntu | esm-apps/jammy | * |
Node-ssri | Ubuntu | focal | * |
Node-ssri | Ubuntu | groovy | * |
Node-ssri | Ubuntu | hirsute | * |
Node-ssri | Ubuntu | impish | * |
Node-ssri | Ubuntu | jammy | * |
Node-ssri | Ubuntu | kinetic | * |
Node-ssri | Ubuntu | trusty | * |
Node-ssri | Ubuntu | upstream | * |