7.5

CVE-2021-27290

Exploit

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ssri ProjectSsri SwPlatformnode.js Version >= 5.2.2 < 6.0.2
Ssri ProjectSsri SwPlatformnode.js Version >= 7.0.0 < 8.0.1
OracleGraalvm Version20.3.3 SwEditionenterprise
OracleGraalvm Version21.2.0 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.67% 0.853
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P