CVE-2021-23362
Summary
| CVE | CVE-2021-23362 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-23 17:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Regular Expression Denial of Service (ReDoS) in hosted-git-info | Snyk |
MISC |
snyk.io |
|
| fix: backport regex fix from #76 · npm/hosted-git-info@29adfe5 · GitHub |
MISC |
github.com |
|
| chore(release): 2.8.9 · npm/hosted-git-info@8d4b369 · GitHub |
MISC |
github.com |
|
| Commits · npm/hosted-git-info · GitHub |
MISC |
github.com |
|
| Regular Expression Denial of Service (ReDoS) in org.webjars.npm:hosted-git-info | Snyk |
MISC |
snyk.io |
|
| cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| fix: simplify the regular expression for shortcut matching · npm/hosted-git-info@bede0dc · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Yeting Li
Legacy QID Mappings
- 159345 Oracle Enterprise Linux Security Update for nodejs:12 (ELSA-2021-3073)
- 159346 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2021-3074)
- 180251 Debian Security Update for node-hosted-git-info (CVE-2021-23362)
- 239531 Red Hat Update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon (RHSA-2021:2932)
- 239532 Red Hat Update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon (RHSA-2021:2931)
- 239547 Red Hat Update for nodejs:14 (RHSA-2021:3074)
- 239548 Red Hat Update for nodejs:12 (RHSA-2021:3073)
- 239654 Red Hat Update for nodejs:12 (RHSA-2021:3639)
- 239655 Red Hat Update for nodejs:12 (RHSA-2021:3638)
- 375692 Node.js Denial Of Service and PATH,DLL hijacking Vulnerabilities July 2021
- 377329 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2021:0056)
- 690034 Free Berkeley Software Distribution (FreeBSD) Security Update for node.js (c174118e-1b11-11ec-9d9d-0022489ad614)
- 750833 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2021:2327-1)
- 750837 SUSE Enterprise Linux Security Update for nodejs10 (SUSE-SU-2021:2353-1)
- 750840 OpenSUSE Security Update for nodejs10 (openSUSE-SU-2021:2353-1)
- 750841 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2021:2354-1)
- 750857 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2021:1060-1)
- 750858 OpenSUSE Security Update for nodejs10 (openSUSE-SU-2021:1061-1)
- 750859 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2021:1059-1)
- 750922 SUSE Enterprise Linux Security Update for nodejs8 (SUSE-SU-2021:2620-1)
- 750928 OpenSUSE Security Update for nodejs8 (openSUSE-SU-2021:2618-1)
- 750939 OpenSUSE Security Update for nodejs8 (openSUSE-SU-2021:1113-1)
- 940245 AlmaLinux Security Update for nodejs:14 (ALSA-2021:3074)
- 940398 AlmaLinux Security Update for nodejs:12 (ALSA-2021:3073)
- 960063 Rocky Linux Security Update for nodejs:14 (RLSA-2021:3074)
- 960082 Rocky Linux Security Update for nodejs:12 (RLSA-2021:3073)
- 982337 Nodejs (npm) Security Update for hosted-git-info (GHSA-43f8-2h32-f4cj)