Bug 2216475 (CVE-2022-25883)
Summary: | CVE-2022-25883 nodejs-semver: Regular expression denial of service | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | ybuenos |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aazores, adudiak, adupliak, aileenc, alampare, alazarot, amctagga, aoconnor, arturo, asoldano, aveerama, bbaranow, bbuckingham, bcourt, bdettelb, bmaxwell, bniver, boliveir, brian.stansberry, cdewolf, chazlett, cluster-maint, darran.lofthouse, davidn, dcadzow, desktop-qa-list, dfreiber, dhanak, dkenigsb, dkreling, dosoudil, drichtar, dsimansk, dymurray, eaguilar, ebaron, ehelms, elima, ellin, emingora, epacific, eric.wittmann, fdeutsch, fjuma, flucifre, fzatlouk, gjospin, gmalinko, gmeno, gparvin, hbraun, hhorak, ibek, ibolton, idevat, idm-ds-dev-bugs, ivassile, iweiss, janstey, jburrell, jcammara, jcantril, jhardy, jkang, jkoehler, jkozol, jkurik, jmatthew, jmontleo, jneedle, jobarker, jorton, jpallich, jrokos, jscotka, jshaughn, jsherril, jwendell, jweng, kshier, kverlaen, lbacciot, lball, lgao, lmorse, lzap, mabashia, matzew, mbenjamin, meda_teja, mhackett, mhulan, michal.skrivanek, mlisik, mnovotny, mosmerov, mperina, mpitt, mpospisi, msochure, mstefank, msvehla, mwringe, myarboro, nathans, nbecker, nboldt, njean, nmoumoul, nodejs-maint, nwallace, ocs-bugs, omular, orabin, oramraz, osapryki, owatkins, pahickey, pantinor, pcpbot, pcreech, pdelbell, pdrozd, peholase, periklis, pjindal, pmackay, pskopek, rcernich, rchan, release-test-team-automation, rgarg, rguimara, rhuss, rjohnson, rogbas, rowaters, rstancel, saroy, sbonazzo, scorneli, scox, sfroberg, sgott, sgratch, shbose, simaishi, skontopo, slucidi, smaestri, smcdonal, smullick, sostapov, sseago, stcannon, sthorger, teagle, tfister, thrcka, tojeline, tom.jenkinson, trathi, twalsh, ubhargav, vereddy, vkumar, yguenane, zsadeh, zsvetlik |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | Flags: | arturo:
needinfo?
(meda_teja) |
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | node-semver 7.5.2, node-semver 6.3.1, node-semver 5.7.2 | Doc Type: | If docs needed, set a value |
Doc Text: |
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in node-semver package via the 'new Range' function. This issue could allow an attacker to pass untrusted malicious regex user data as a range, causing the service to excessively consume CPU depending upon the input size, resulting in a denial of service.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2023-08-02 18:10:14 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2217402, 2222507, 2222508, 2222509, 2222510, 2222512, 2222527, 2222511, 2222513, 2222514, 2222515, 2222516, 2222517, 2222518, 2222519, 2222520, 2222521, 2222522, 2222523, 2222524, 2222525, 2222528, 2222529, 2222530, 2222531, 2222532, 2222533, 2222534, 2222535, 2222536, 2222537, 2222538, 2222539, 2222540, 2222541, 2222542, 2222544, 2222545, 2222546, 2222547, 2222548, 2222549, 2222550, 2222551, 2222552, 2222553, 2222561, 2222562, 2222563, 2222564, 2222565, 2222566, 2222567, 2222568, 2222569, 2234408, 2234413, 2234449, 2234450 | ||
Bug Blocks: | 2216477 |
Description
ybuenos
2023-06-21 14:38:29 UTC
Created nodejs-semver tracking bugs for this issue: Affects: epel-7 [bug 2217402] This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products. Created breeze-icon-theme tracking bugs for this issue: Affects: epel-all [bug 2222507] Affects: fedora-all [bug 2222513] Created cachelib tracking bugs for this issue: Affects: fedora-all [bug 2222514] Created fbthrift tracking bugs for this issue: Affects: fedora-all [bug 2222515] Created golang-github-prometheus tracking bugs for this issue: Affects: epel-all [bug 2222508] Created llhttp tracking bugs for this issue: Affects: fedora-all [bug 2222516] Created mozjs78 tracking bugs for this issue: Affects: fedora-all [bug 2222517] Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222518] Created nodejs-bash-language-server tracking bugs for this issue: Affects: fedora-all [bug 2222519] Created nodejs:13/nodejs tracking bugs for this issue: Affects: epel-all [bug 2222509] Created nodejs:16-epel/nodejs tracking bugs for this issue: Affects: epel-all [bug 2222510] Created nodejs:16/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222520] Created nodejs:18/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222521] Created pgadmin4 tracking bugs for this issue: Affects: fedora-all [bug 2222522] Created rstudio tracking bugs for this issue: Affects: fedora-all [bug 2222523] Created seamonkey tracking bugs for this issue: Affects: epel-all [bug 2222511] Affects: fedora-all [bug 2222524] Created yarnpkg tracking bugs for this issue: Affects: epel-all [bug 2222512] Affects: fedora-all [bug 2222525] This issue has been addressed in the following products: RHOL-5.7-RHEL-8 Via RHSA-2023:4341 https://access.redhat.com/errata/RHSA-2023:4341 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-25883 @ @trathi I see a comment here: "This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products." But then I see online that this CVE includes many commercial redhat products: https://access.redhat.com/security/cve/cve-2022-25883 Specifically I'm interested in RHEL8 distributions. Is there any work in progress to remediate this? In reply to comment #19: > @trathi I see a comment here: "This CVE Bugzilla entry is for > community support informational purposes only as it does not affect a > package in a commercially supported Red Hat product. Refer to the dependent > bugs for status of those individual community products." But then I see > online that this CVE includes many commercial redhat products: > https://access.redhat.com/security/cve/cve-2022-25883 Specifically I'm > interested in RHEL8 distributions. Is there any work in progress to > remediate this? Hey, not really. That comment was auto-generated just because - there were only community products (fedora, and epel) added to this CVE, and bugzilla prodsec bot auto closed it, thinking that this only affects community products. But, later, we added Red Hat Products which were affected by this CVE and the bug was reopened. And, for rhel distributions, yes fixes are in progress. @trathi Any eta on this? In reply to comment #21: > @trathi Any eta on this? Some updates for RHEL-8 will be out soon (By the end of this week or early next week). This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5361 https://access.redhat.com/errata/RHSA-2023:5361 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5363 https://access.redhat.com/errata/RHSA-2023:5363 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5360 https://access.redhat.com/errata/RHSA-2023:5360 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5362 https://access.redhat.com/errata/RHSA-2023:5362 Thanks for addressing this! This issue has been addressed in the following products: NETWORK-OBSERVABILITY-1.4.0-RHEL-9 Via RHSA-2023:5379 https://access.redhat.com/errata/RHSA-2023:5379 @trathi The RedHat CVE report (https://access.redhat.com/security/cve/CVE-2022-25883) says this bug is fixed but when I look at the following images, the semver package is still vulnerable: $ docker run -it -u root --rm registry.access.redhat.com/ubi8/nodejs-16-minimal bash bash-4.4# cat /usr/lib/node_modules/npm/node_modules/semver/package.json | grep -A1 semver "name": "semver", "version": "7.3.7", $ docker run -it -u root --rm registry.access.redhat.com/ubi8/nodejs-18-minimal bash bash-4.4# cat /usr/lib/node_modules/npm/node_modules/semver/package.json | grep -A1 semver "name": "semver", "version": "7.5.1", It's the same for the node 16/18 UBI9 images as well. I have also seen the semver at the levels above. Do we know when it will be fixed? This issue has been addressed in the following products: EAP 7.4.13 Via RHSA-2023:5488 https://access.redhat.com/errata/RHSA-2023:5488 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2023:5484 https://access.redhat.com/errata/RHSA-2023:5484 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2023:5485 https://access.redhat.com/errata/RHSA-2023:5485 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2023:5486 https://access.redhat.com/errata/RHSA-2023:5486 @trathi any update on my comment above: https://bugzilla.redhat.com/show_bug.cgi?id=2216475#c29 ? The CVE https://access.redhat.com/security/cve/cve-2022-25883 says this is fixed in those images but the vulnerability is still showing up. This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2023:7222 https://access.redhat.com/errata/RHSA-2023:7222 This issue has been addressed in the following products: Migration Toolkit for Runtimes 1 on RHEL 8 Via RHSA-2024:0719 https://access.redhat.com/errata/RHSA-2024:0719 Marking EAP-8 as not affected because EAP 8 GA was released with the fixed version of nodejs-semver. |