CVE-2021-23343
Summary
| CVE | CVE-2021-23343 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-04 09:15:00 UTC |
| Updated | 2023-11-07 03:30:00 UTC |
| Description | All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Path-parse Project | Path-parse | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Invalid vulnerability | MISC | snyk.io | |
| [myfaces-dev] 20210531 Re: [VOTE] Release Tobago 4.5.4, 5.0.0-alpha-1 and checkstyle-rules 14 | lists.apache.org | ||
| ReDoS in path-parse · Issue #8 · jbgutierrez/path-parse · GitHub | MISC | github.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Invalid vulnerability | MISC | snyk.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Yeting Li
Legacy QID Mappings
- 159398 Oracle Enterprise Linux Security Update for nodejs:12 (ELSA-2021-3623)
- 159408 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2021-3666)
- 239590 Red Hat Update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon (RHSA-2021:3281)
- 239591 Red Hat Update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon (RHSA-2021:3280)
- 239645 Red Hat Update for nodejs:12 (RHSA-2021:3623)
- 239654 Red Hat Update for nodejs:12 (RHSA-2021:3639)
- 239655 Red Hat Update for nodejs:12 (RHSA-2021:3638)
- 239658 Red Hat Update for nodejs:14 (RHSA-2021:3666)
- 377157 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2021:0072)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 751759 SUSE Enterprise Linux Security Update for nodejs8 (SUSE-SU-2022:0563-1)
- 751773 SUSE Enterprise Linux Security Update for nodejs12 (SUSE-SU-2022:0657-1)
- 751781 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2022:0657-1)
- 751783 SUSE Enterprise Linux Security Update for nodejs8 (SUSE-SU-2022:0704-1)
- 751801 SUSE Enterprise Linux Security Update for nodejs14 (SUSE-SU-2022:0715-1)
- 751820 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2022:0715-1)
- 751824 OpenSUSE Security Update for nodejs8 (openSUSE-SU-2022:0704-1)
- 751826 OpenSUSE Security Update for nodejs8 (openSUSE-SU-22022:20000-2)
- 752142 SUSE Enterprise Linux Security Update for nodejs10 (SUSE-SU-2022:1717-1)
- 940217 AlmaLinux Security Update for nodejs:12 (ALSA-2021:3623)
- 940388 AlmaLinux Security Update for nodejs:14 (ALSA-2021:3666)
- 960018 Rocky Linux Security Update for nodejs:12 (RLSA-2021:3623)
- 960050 Rocky Linux Security Update for nodejs:14 (RLSA-2021:3666)
- 981715 Nodejs (npm) Security Update for path-parse (GHSA-hj48-42vr-x3v9)