CVE Vulnerabilities

CVE-2021-27290

Published: Mar 12, 2021 | Modified: May 13, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Affected Software

Name Vendor Start Version End Version
Ssri Ssri_project 5.2.2 (including) 6.0.2 (excluding)
Ssri Ssri_project 7.0.0 (including) 8.0.1 (excluding)
Red Hat Enterprise Linux 8 RedHat nodejs:12-8040020210708131418.522a0ee4 *
Red Hat Enterprise Linux 8 RedHat nodejs:14-8040020210708154809.522a0ee4 *
Red Hat Enterprise Linux 8.1 Extended Update Support RedHat nodejs:12-8010020210817113128.c27ad7f8 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat nodejs:12-8020020210817125332.4cda2c84 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-nodejs12-nodejs-0:12.22.2-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-nodejs12-nodejs-nodemon-0:2.0.3-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-nodejs14-nodejs-0:14.17.2-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-nodejs14-nodejs-nodemon-0:2.0.3-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-nodejs12-nodejs-0:12.22.2-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-nodejs12-nodejs-nodemon-0:2.0.3-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-nodejs14-nodejs-0:14.17.2-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-nodejs14-nodejs-nodemon-0:2.0.3-2.el7 *
Node-ssri Ubuntu esm-apps/focal *
Node-ssri Ubuntu esm-apps/jammy *
Node-ssri Ubuntu focal *
Node-ssri Ubuntu groovy *
Node-ssri Ubuntu hirsute *
Node-ssri Ubuntu impish *
Node-ssri Ubuntu jammy *
Node-ssri Ubuntu kinetic *
Node-ssri Ubuntu trusty *
Node-ssri Ubuntu upstream *

References