A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Minimatch | Minimatch_project | * | 3.0.5 (excluding) |
Migration Toolkit for Runtimes 1 on RHEL 8 | RedHat | nodejs-minimatch | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-governance-policy-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-grafana-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-must-gather-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-operator-bundle-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-prometheus-config-reloader-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-prometheus-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-volsync-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cert-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cluster-backup-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | config-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | console-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | endpoint-monitoring-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-propagator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-spec-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-status-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-template-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | grafana-dashboard-loader-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | iam-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-client-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | klusterlet-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-rbac-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-state-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | management-ingress-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | metrics-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicloud-integrations-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-repo-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-observability-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-application-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-channel-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-subscription-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | node-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-alertmanager-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rbac-query-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | redisgraph-tls-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-aggregator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-api-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | submariner-addon-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-receive-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 | RedHat | rhacm2/console-rhel8:v2.7.0-125 | * |
Red Hat Enterprise Linux 8 | RedHat | nodejs:18-8070020221118123310.bd1311ed | * |
Red Hat Enterprise Linux 8 | RedHat | nodejs:16-8070020221207164159.bd1311ed | * |
Red Hat Enterprise Linux 8 | RedHat | nodejs:14-8070020221212161539.bd1311ed | * |
Red Hat Enterprise Linux 8 | RedHat | nodejs:14-8070020230306170042.bd1311ed | * |
Red Hat Enterprise Linux 8.4 Extended Update Support | RedHat | nodejs:14-8040020230306170312.522a0ee4 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | nodejs:14-8060020230306170237.ad008a3a | * |
Red Hat Enterprise Linux 9 | RedHat | nodejs:18-9010020221118120946.rhel9 | * |
Red Hat Enterprise Linux 9 | RedHat | nodejs-1:16.18.1-3.el9_1 | * |
Red Hat Enterprise Linux 9 | RedHat | nodejs-nodemon-0:2.0.20-2.el9_1 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-nodejs14-nodejs-0:14.21.1-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-nodejs14-nodejs-nodemon-0:2.0.20-2.el7 | * |
RHODF-4.13-RHEL-9 | RedHat | odf4/mcg-core-rhel9:v4.13.0-41 | * |
Node-minimatch | Ubuntu | bionic | * |
Node-minimatch | Ubuntu | focal | * |
Node-minimatch | Ubuntu | trusty | * |
Node-minimatch | Ubuntu | upstream | * |
Node-minimatch | Ubuntu | xenial | * |
Attackers can create crafted inputs that
intentionally cause the regular expression to use
excessive backtracking in a way that causes the CPU
consumption to spike.