7.5

CVE-2021-27290

Exploit
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ssri Project ≫ Ssri SwPlatform node.js Version >= 5.2.2 < 6.0.2
Ssri Project ≫ Ssri SwPlatform node.js Version >= 7.0.0 < 8.0.1
Oracle ≫ Graalvm Version 20.3.3 SwEdition enterprise
Oracle ≫ Graalvm Version 21.2.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.72% 0.907
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
Patch
Third Party Advisory
https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf
Patch
Third Party Advisory
Exploit
https://github.com/yetingli/SaveResults/blob/main/pdf/ssri-redos.pdf
Third Party Advisory
Exploit
https://npmjs.com
Product