Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range. https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795 https://github.com/npm/node-semver/pull/564 https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
Created nodejs-semver tracking bugs for this issue: Affects: epel-7 [bug 2217402]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Created breeze-icon-theme tracking bugs for this issue: Affects: epel-all [bug 2222507] Affects: fedora-all [bug 2222513] Created cachelib tracking bugs for this issue: Affects: fedora-all [bug 2222514] Created fbthrift tracking bugs for this issue: Affects: fedora-all [bug 2222515] Created golang-github-prometheus tracking bugs for this issue: Affects: epel-all [bug 2222508] Created llhttp tracking bugs for this issue: Affects: fedora-all [bug 2222516] Created mozjs78 tracking bugs for this issue: Affects: fedora-all [bug 2222517] Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222518] Created nodejs-bash-language-server tracking bugs for this issue: Affects: fedora-all [bug 2222519] Created nodejs:13/nodejs tracking bugs for this issue: Affects: epel-all [bug 2222509] Created nodejs:16-epel/nodejs tracking bugs for this issue: Affects: epel-all [bug 2222510] Created nodejs:16/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222520] Created nodejs:18/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222521] Created pgadmin4 tracking bugs for this issue: Affects: fedora-all [bug 2222522] Created rstudio tracking bugs for this issue: Affects: fedora-all [bug 2222523] Created seamonkey tracking bugs for this issue: Affects: epel-all [bug 2222511] Affects: fedora-all [bug 2222524] Created yarnpkg tracking bugs for this issue: Affects: epel-all [bug 2222512] Affects: fedora-all [bug 2222525]
This issue has been addressed in the following products: RHOL-5.7-RHEL-8 Via RHSA-2023:4341 https://access.redhat.com/errata/RHSA-2023:4341
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-25883