Bug 2159959 (CVE-2023-22467) - CVE-2023-22467 luxon: Inefficient regular expression complexity in luxon.js
Summary: CVE-2023-22467 luxon: Inefficient regular expression complexity in luxon.js
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2023-22467
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2159961 2164326
Blocks: 2158311
TreeView+ depends on / blocked
 
Reported: 2023-01-11 08:19 UTC by ybuenos
Modified: 2023-05-02 16:39 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-02-10 06:29:59 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:0630 0 None None None 2023-02-07 18:37:03 UTC

Description ybuenos 2023-01-11 08:19:01 UTC
Luxon is a library for working with dates and times in JavaScript. On the 1.x branch prior to 1.38.1, the 2.x branch prior to 2.5.2, and the 3.x branch on 3.2.1, Luxon's `DateTime.fromRFC2822() has quadratic (N^2) complexity on some specific inputs. This causes a noticeable slowdown for inputs with lengths above 10k characters. Users providing untrusted data to this method are therefore vulnerable to (Re)DoS attacks. This issue also appears in Moment as CVE-2022-31129. Versions 1.38.1, 2.5.2, and 3.2.1 contain patches for this issue. As a workaround, limit the length of the input.

https://github.com/moment/moment/pull/6015#issuecomment-1152961973
https://github.com/moment/luxon/commit/5ab3bf64a10da929a437629cdb2f059bb83212bf
https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g
https://github.com/moment/luxon/security/advisories/GHSA-3xq5-wjfh-ppjc

Comment 1 ybuenos 2023-01-11 08:19:16 UTC
Created python-nikola tracking bugs for this issue:

Affects: fedora-all [bug 2159961]

Comment 7 errata-xmlrpc 2023-02-07 18:37:01 UTC
This issue has been addressed in the following products:

  Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8

Via RHSA-2023:0630 https://access.redhat.com/errata/RHSA-2023:0630

Comment 8 Product Security DevOps Team 2023-02-10 06:29:56 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2023-22467


Note You need to log in before you can comment on or make changes to this bug.