Bug 2216475 (CVE-2022-25883) - CVE-2022-25883 nodejs-semver: Regular expression denial of service
Summary: CVE-2022-25883 nodejs-semver: Regular expression denial of service
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-25883
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2217402 2222507 2222508 2222509 2222510 2222512 2222513 2222514 2222515 2222517 2222518 2222519 2222520 2222521 2222522 2222525 2222527 2222528 2222529 2222530 2222531 2222532 2222533 2222534 2222535 2222536 2222537 2222538 2222539 2222540 2222544 2222545 2222546 2222547 2222548 2222549 2222550 2222562 2234408 2234413 2234449 2234450 2222511 2222516 2222523 2222524 2222541 2222542 2222551 2222552 2222553 2222561 2222563 2222564 2222565 2222566 2222567 2222568 2222569
Blocks: 2216477
TreeView+ depends on / blocked
 
Reported: 2023-06-21 14:38 UTC by ybuenos
Modified: 2023-08-24 13:12 UTC (History)
166 users (show)

Fixed In Version: node-semver 7.5.2, node-semver 6.3.1, node-semver 5.7.2
Doc Type: If docs needed, set a value
Doc Text:
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in node-semver package via the 'new Range' function. This issue could allow an attacker to pass untrusted malicious regex user data as a range, causing the service to excessively consume CPU depending upon the input size, resulting in a denial of service.
Clone Of:
Environment:
Last Closed: 2023-08-02 18:10:14 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:4341 0 None None None 2023-08-02 13:49:51 UTC

Description ybuenos 2023-06-21 14:38:29 UTC
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795
https://github.com/npm/node-semver/pull/564
https://github.com/advisories/GHSA-c2qf-rxjj-qqgw

Comment 1 Sandipan Roy 2023-06-26 07:55:46 UTC
Created nodejs-semver tracking bugs for this issue:

Affects: epel-7 [bug 2217402]

Comment 2 Product Security DevOps Team 2023-06-26 12:04:53 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.

Comment 4 TEJ RATHI 2023-07-13 04:39:56 UTC
Created breeze-icon-theme tracking bugs for this issue:

Affects: epel-all [bug 2222507]
Affects: fedora-all [bug 2222513]


Created cachelib tracking bugs for this issue:

Affects: fedora-all [bug 2222514]


Created fbthrift tracking bugs for this issue:

Affects: fedora-all [bug 2222515]


Created golang-github-prometheus tracking bugs for this issue:

Affects: epel-all [bug 2222508]


Created llhttp tracking bugs for this issue:

Affects: fedora-all [bug 2222516]


Created mozjs78 tracking bugs for this issue:

Affects: fedora-all [bug 2222517]


Created nodejs tracking bugs for this issue:

Affects: fedora-all [bug 2222518]


Created nodejs-bash-language-server tracking bugs for this issue:

Affects: fedora-all [bug 2222519]


Created nodejs:13/nodejs tracking bugs for this issue:

Affects: epel-all [bug 2222509]


Created nodejs:16-epel/nodejs tracking bugs for this issue:

Affects: epel-all [bug 2222510]


Created nodejs:16/nodejs tracking bugs for this issue:

Affects: fedora-all [bug 2222520]


Created nodejs:18/nodejs tracking bugs for this issue:

Affects: fedora-all [bug 2222521]


Created pgadmin4 tracking bugs for this issue:

Affects: fedora-all [bug 2222522]


Created rstudio tracking bugs for this issue:

Affects: fedora-all [bug 2222523]


Created seamonkey tracking bugs for this issue:

Affects: epel-all [bug 2222511]
Affects: fedora-all [bug 2222524]


Created yarnpkg tracking bugs for this issue:

Affects: epel-all [bug 2222512]
Affects: fedora-all [bug 2222525]

Comment 16 errata-xmlrpc 2023-08-02 13:49:42 UTC
This issue has been addressed in the following products:

  RHOL-5.7-RHEL-8

Via RHSA-2023:4341 https://access.redhat.com/errata/RHSA-2023:4341

Comment 17 Product Security DevOps Team 2023-08-02 18:10:04 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-25883


Note You need to log in before you can comment on or make changes to this bug.