Red Hat Bugzilla – Bug 1500705
CVE-2017-16137 nodejs-debug: Regular expression Denial of Service
Last modified: 2018-07-04 10:12:02 EDT
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue. Upstream issue: https://github.com/visionmedia/debug/issues/501 Upstream pull request: https://github.com/visionmedia/debug/pull/504
Created nodejs-debug tracking bugs for this issue: Affects: fedora-all [bug 1500706]
Statement: This issue affects the versions of rh-nodejs4-nodejs-debug, rh-nodejs6-nodejs-debug, and rh-nodejs8-nodejs-debug as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Created nodejs-debug tracking bugs for this issue: Affects: openshift-1 [bug 1516740]
debug formatters.o method not used in RHMAP. Marking as not affected.