Bug 2126277 (CVE-2022-25858) - CVE-2022-25858 terser: insecure use of regular expressions leads to ReDoS
Summary: CVE-2022-25858 terser: insecure use of regular expressions leads to ReDoS
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-25858
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2126278 2126279 2126280 2126281 2126282 2126283 2126284 2126285 2126310 2126311 2126312 2126313 2126314 2126343 2126344 2126345 2126346 2126713 2126715
Blocks: 2126196
TreeView+ depends on / blocked
 
Reported: 2022-09-13 05:04 UTC by Avinash Hanwate
Modified: 2023-09-01 04:00 UTC (History)
123 users (show)

Fixed In Version: terser 4.8.1, terser 5.14.2
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in the terser package. Affected versions of this package are vulnerable to Regular expression denial of service (ReDoS) attacks, affecting system availability.
Clone Of:
Environment:
Last Closed: 2022-12-03 05:04:23 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2022:6835 0 None None None 2022-10-06 12:28:23 UTC
Red Hat Product Errata RHSA-2022:7276 0 None None None 2022-11-01 16:55:53 UTC
Red Hat Product Errata RHSA-2022:7313 0 None None None 2022-11-02 14:07:53 UTC
Red Hat Product Errata RHSA-2023:3645 0 None None None 2023-06-15 20:56:22 UTC

Comment 1 Sandipan Roy 2022-09-13 05:18:59 UTC
Created cockatrice tracking bugs for this issue:

Affects: fedora-all [bug 2126279]


Created golang-entgo-ent tracking bugs for this issue:

Affects: fedora-all [bug 2126280]


Created golang-github-prometheus tracking bugs for this issue:

Affects: epel-7 [bug 2126278]


Created grafana tracking bugs for this issue:

Affects: fedora-all [bug 2126281]


Created zuul tracking bugs for this issue:

Affects: fedora-all [bug 2126282]

Comment 8 errata-xmlrpc 2022-10-06 12:28:17 UTC
This issue has been addressed in the following products:

  RHINT Service Registry 2.3.0 GA

Via RHSA-2022:6835 https://access.redhat.com/errata/RHSA-2022:6835

Comment 11 errata-xmlrpc 2022-11-01 16:55:47 UTC
This issue has been addressed in the following products:

  Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8

Via RHSA-2022:7276 https://access.redhat.com/errata/RHSA-2022:7276

Comment 12 errata-xmlrpc 2022-11-02 14:07:46 UTC
This issue has been addressed in the following products:

  Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8

Via RHSA-2022:7313 https://access.redhat.com/errata/RHSA-2022:7313

Comment 15 Product Security DevOps Team 2022-12-03 05:04:18 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-25858

Comment 19 errata-xmlrpc 2023-06-15 20:56:16 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Service Mesh 2.2 for RHEL 8

Via RHSA-2023:3645 https://access.redhat.com/errata/RHSA-2023:3645


Note You need to log in before you can comment on or make changes to this bug.