CVE-2021-35065
Summary
| CVE | CVE-2021-35065 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-26 07:15:00 UTC |
| Updated | 2023-01-23 18:32:00 UTC |
| Description | The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Gulpjs |
Glob-parent |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| fix: Resolve ReDoS vulnerability from CVE-2021-35065 (#49) · gulpjs/glob-parent@3e9f04a · GitHub |
CONFIRM |
github.com |
|
| fix: Fix ReDoS vulnerability CVE-2021-35065 by sttk · Pull Request #49 · gulpjs/glob-parent · GitHub |
CONFIRM |
github.com |
|
| Regular Expression Denial of Service (ReDoS) in glob-parent | CVE-2021-35065 | Snyk |
MISC |
security.snyk.io |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160533 Oracle Enterprise Linux Security Update for nodejs:18 (ELSA-2023-1583)
- 160535 Oracle Enterprise Linux Security Update for nodejs:16 (ELSA-2023-1582)
- 160547 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2023-1743)
- 160639 Oracle Enterprise Linux Security Update for nodejs:18 (ELSA-2023-2654)
- 182496 Debian Security Update for node-glob-parent (CVE-2021-35065)
- 241160 Red Hat Update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon (RHSA-2023:0612)
- 241304 Red Hat Update for nodejs:14 security (RHSA-2023:1533)
- 241307 Red Hat Update for nodejs:18 security (RHSA-2023:1583)
- 241332 Red Hat Update for nodejs:16 security (RHSA-2023:1582)
- 241341 Red Hat Update for nodejs:14 security (RHSA-2023:1742)
- 241342 Red Hat Update for nodejs:14 security (RHSA-2023:1743)
- 241457 Red Hat Update for nodejs:18 security (RHSA-2023:2654)
- 283594 Fedora Security Update for pgadmin4 (FEDORA-2023-496439cbdd)
- 283595 Fedora Security Update for yarnpkg (FEDORA-2023-8d4b772755)
- 283596 Fedora Security Update for yarnpkg (FEDORA-2023-5c6f32db6f)
- 378467 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2023:0037)
- 940976 AlmaLinux Security Update for nodejs:16 (ALSA-2023:1582)
- 940977 AlmaLinux Security Update for nodejs:18 (ALSA-2023:1583)
- 940979 AlmaLinux Security Update for nodejs:14 (ALSA-2023:1743)
- 941014 AlmaLinux Security Update for nodejs:18 (ALSA-2023:2654)
- 960893 Rocky Linux Security Update for nodejs:18 (RLSA-2023:1583)
- 960902 Rocky Linux Security Update for nodejs:16 (RLSA-2023:1582)
- 960917 Rocky Linux Security Update for nodejs:14 (RLSA-2023:1743)