CVE Vulnerabilities

CVE-2022-25883

Inefficient Regular Expression Complexity

Published: Jun 21, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

Weakness

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Affected Software

Name Vendor Start Version End Version
Semver Npmjs * 5.7.2 (excluding)
Semver Npmjs 6.0.0 (including) 6.3.1 (excluding)
Semver Npmjs 7.0.0 (including) 7.5.2 (excluding)
EAP 7.4.13 RedHat nodejs-semver *
Migration Toolkit for Runtimes 1 on RHEL 8 RedHat mtr/mtr-web-container-rhel8:1.2-10 *
Migration Toolkit for Runtimes 1 on RHEL 8 RedHat mtr/mtr-web-executor-container-rhel8:1.2-8 *
Multicluster engine for Kubernetes 2.6 for RHEL 8 RedHat multicluster-engine/assisted-image-service-rhel8:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 8 RedHat multicluster-engine/assisted-installer-agent-rhel8:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 8 RedHat multicluster-engine/assisted-installer-controller-rhel8:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 8 RedHat multicluster-engine/assisted-installer-rhel8:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 8 RedHat multicluster-engine/assisted-service-8-rhel8:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/addon-manager-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/assisted-service-9-rhel9:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/backplane-rhel9-operator:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/cluster-api-provider-agent-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/cluster-api-provider-kubevirt-rhel9:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/cluster-api-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/clusterclaims-controller-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/cluster-curator-controller-rhel9:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/cluster-image-set-controller-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/clusterlifecycle-state-metrics-rhel9:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/cluster-proxy-addon-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/cluster-proxy-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/console-mce-rhel9:v2.6.2-8 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/discovery-rhel9:v2.6.2-9 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/hive-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/hypershift-addon-rhel9-operator:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/hypershift-cli-rhel9:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/hypershift-rhel9-operator:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/image-based-install-rhel9:v2.6.2-22 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/kube-rbac-proxy-mce-rhel9:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/managedcluster-import-controller-rhel9:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/managed-serviceaccount-rhel9:v2.6.2-8 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/mce-operator-bundle:v2.6.2-13 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/multicloud-manager-rhel9:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/multicluster-engine-cluster-api-provider-agent-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/multicluster-engine-console-mce-rhel9:v2.6.2-8 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/multicluster-engine-hypershift-addon-rhel9-operator:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/multicluster-engine-managed-serviceaccount-rhel9:v2.6.2-8 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/must-gather-rhel9:v2.6.2-5 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/placement-rhel9:v2.6.2-6 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/provider-credential-controller-rhel9:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/registration-operator-rhel9:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/registration-rhel9:v2.6.2-7 *
Multicluster engine for Kubernetes 2.6 for RHEL 9 RedHat multicluster-engine/work-rhel9:v2.6.2-7 *
NETWORK-OBSERVABILITY-1.4.0-RHEL-9 RedHat network-observability/network-observability-console-plugin-rhel9:v1.4.0-42 *
NETWORK-OBSERVABILITY-1.4.0-RHEL-9 RedHat network-observability/network-observability-ebpf-agent-rhel9:v1.4.0-42 *
NETWORK-OBSERVABILITY-1.4.0-RHEL-9 RedHat network-observability/network-observability-flowlogs-pipeline-rhel9:v1.4.0-42 *
NETWORK-OBSERVABILITY-1.4.0-RHEL-9 RedHat network-observability/network-observability-operator-bundle:1.4.0-55 *
NETWORK-OBSERVABILITY-1.4.0-RHEL-9 RedHat network-observability/network-observability-rhel9-operator:v1.4.0-42 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-cluster-permission-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-governance-policy-addon-controller-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-governance-policy-framework-addon-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-grafana-rhel9:v2.11.2-4 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-must-gather-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-operator-bundle:v2.11.2-18 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-prometheus-config-reloader-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-prometheus-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-search-indexer-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-search-v2-api-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-search-v2-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-volsync-addon-controller-rhel9:v2.11.2-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/cert-policy-controller-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/cluster-backup-rhel9-operator:v2.11.2-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/config-policy-controller-rhel9:v2.11.2-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/console-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/endpoint-monitoring-rhel9-operator:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/governance-policy-propagator-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/grafana-dashboard-loader-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/insights-client-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/insights-metrics-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/klusterlet-addon-controller-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/kube-rbac-proxy-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/kube-state-metrics-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/memcached-exporter-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/memcached-rhel9:v2.11.2-4 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/metrics-collector-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicloud-integrations-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multiclusterhub-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-observability-rhel9-operator:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-operators-application-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-operators-channel-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-operators-subscription-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/node-exporter-rhel9:v2.11.2-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/observatorium-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/observatorium-rhel9-operator:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/prometheus-alertmanager-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/prometheus-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/rbac-query-proxy-rhel9:v2.11.2-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/search-collector-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/submariner-addon-rhel9:v2.11.2-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/thanos-receive-controller-rhel9:v2.11.2-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/thanos-rhel9:v2.11.2-6 *
Red Hat Enterprise Linux 8 RedHat nodejs:16-8080020230906092006.63b34585 *
Red Hat Enterprise Linux 8 RedHat nodejs:18-8080020230825111344.63b34585 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat nodejs:16-8060020230906023909.ad008a3a *
Red Hat Enterprise Linux 9 RedHat nodejs:18-9020020230825081254.rhel9 *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-activemq-artemis-0:2.16.0-15.redhat_00049.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-bouncycastle-0:1.76.0-4.redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-hal-console-0:3.3.19-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-hibernate-0:5.3.31-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-ironjacamar-0:1.5.15-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-marshalling-0:2.0.13-2.SP1_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-modules-0:1.12.2-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-server-migration-0:1.10.0-31.Final_redhat_00030.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-xnio-base-0:3.8.10-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-mod_cluster-0:1.4.5-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-netty-0:4.1.94-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-netty-transport-native-epoll-0:4.1.94-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-resteasy-0:3.15.8-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-undertow-0:2.2.26-1.SP1_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-0:7.4.13-8.GA_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-elytron-0:1.15.20-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-activemq-artemis-0:2.16.0-15.redhat_00049.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-bouncycastle-0:1.76.0-4.redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-hal-console-0:3.3.19-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-hibernate-0:5.3.31-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-ironjacamar-0:1.5.15-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-marshalling-0:2.0.13-2.SP1_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-modules-0:1.12.2-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-server-migration-0:1.10.0-31.Final_redhat_00030.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-xnio-base-0:3.8.10-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-mod_cluster-0:1.4.5-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-netty-0:4.1.94-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-netty-transport-native-epoll-0:4.1.94-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-resteasy-0:3.15.8-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-undertow-0:2.2.26-1.SP1_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-0:7.4.13-8.GA_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-elytron-0:1.15.20-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-activemq-artemis-0:2.16.0-15.redhat_00049.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-bouncycastle-0:1.76.0-4.redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-hal-console-0:3.3.19-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-hibernate-0:5.3.31-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-ironjacamar-0:1.5.15-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jboss-marshalling-0:2.0.13-2.SP1_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jboss-modules-0:1.12.2-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jboss-server-migration-0:1.10.0-31.Final_redhat_00030.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jboss-xnio-base-0:3.8.10-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-mod_cluster-0:1.4.5-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-netty-0:4.1.94-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-netty-transport-native-epoll-0:4.1.94-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-resteasy-0:3.15.8-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-undertow-0:2.2.26-1.SP1_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-wildfly-0:7.4.13-8.GA_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-wildfly-elytron-0:1.15.20-1.Final_redhat_00001.1.el7eap *
Red Hat Migration Toolkit for Containers 1.8 RedHat rhmtc/openshift-migration-ui-rhel8:v1.8.2-2 *
RHOL-5.7-RHEL-8 RedHat openshift-logging/logging-view-plugin-rhel8:v5.7.4-4 *
Node-semver Ubuntu bionic *
Node-semver Ubuntu kinetic *
Node-semver Ubuntu lunar *
Node-semver Ubuntu mantic *
Node-semver Ubuntu trusty *
Node-semver Ubuntu xenial *

Extended Description

	  Attackers can create crafted inputs that
	  intentionally cause the regular expression to use
	  excessive backtracking in a way that causes the CPU
	  consumption to spike.

Potential Mitigations

References