7.5

CVE-2021-27290

Exploit

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Data is provided by the National Vulnerability Database (NVD)
Ssri ProjectSsri SwPlatformnode.js Version >= 5.2.2 < 6.0.2
Ssri ProjectSsri SwPlatformnode.js Version >= 7.0.0 < 8.0.1
OracleGraalvm Version20.3.3 SwEditionenterprise
OracleGraalvm Version21.2.0 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.67% 0.853
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P