CVE Vulnerabilities

CVE-2021-29469

Published: Apr 23, 2021 | Modified: Aug 03, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service. The issue is patched in version 3.1.1.

Affected Software

Name Vendor Start Version End Version
Redis Redis.js * 3.1.1 (excluding)
Node-redis Ubuntu bionic *
Node-redis Ubuntu groovy *
Node-redis Ubuntu hirsute *
Node-redis Ubuntu impish *
Node-redis Ubuntu kinetic *
Node-redis Ubuntu trusty *
Node-redis Ubuntu upstream *
Node-redis Ubuntu xenial *

References