Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range. https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795 https://github.com/npm/node-semver/pull/564 https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
Created nodejs-semver tracking bugs for this issue: Affects: epel-7 [bug 2217402]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Created breeze-icon-theme tracking bugs for this issue: Affects: epel-all [bug 2222507] Affects: fedora-all [bug 2222513] Created cachelib tracking bugs for this issue: Affects: fedora-all [bug 2222514] Created fbthrift tracking bugs for this issue: Affects: fedora-all [bug 2222515] Created golang-github-prometheus tracking bugs for this issue: Affects: epel-all [bug 2222508] Created llhttp tracking bugs for this issue: Affects: fedora-all [bug 2222516] Created mozjs78 tracking bugs for this issue: Affects: fedora-all [bug 2222517] Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222518] Created nodejs-bash-language-server tracking bugs for this issue: Affects: fedora-all [bug 2222519] Created nodejs:13/nodejs tracking bugs for this issue: Affects: epel-all [bug 2222509] Created nodejs:16-epel/nodejs tracking bugs for this issue: Affects: epel-all [bug 2222510] Created nodejs:16/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222520] Created nodejs:18/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2222521] Created pgadmin4 tracking bugs for this issue: Affects: fedora-all [bug 2222522] Created rstudio tracking bugs for this issue: Affects: fedora-all [bug 2222523] Created seamonkey tracking bugs for this issue: Affects: epel-all [bug 2222511] Affects: fedora-all [bug 2222524] Created yarnpkg tracking bugs for this issue: Affects: epel-all [bug 2222512] Affects: fedora-all [bug 2222525]
This issue has been addressed in the following products: RHOL-5.7-RHEL-8 Via RHSA-2023:4341 https://access.redhat.com/errata/RHSA-2023:4341
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-25883
@
@trathi I see a comment here: "This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products." But then I see online that this CVE includes many commercial redhat products: https://access.redhat.com/security/cve/cve-2022-25883 Specifically I'm interested in RHEL8 distributions. Is there any work in progress to remediate this?
In reply to comment #19: > @trathi I see a comment here: "This CVE Bugzilla entry is for > community support informational purposes only as it does not affect a > package in a commercially supported Red Hat product. Refer to the dependent > bugs for status of those individual community products." But then I see > online that this CVE includes many commercial redhat products: > https://access.redhat.com/security/cve/cve-2022-25883 Specifically I'm > interested in RHEL8 distributions. Is there any work in progress to > remediate this? Hey, not really. That comment was auto-generated just because - there were only community products (fedora, and epel) added to this CVE, and bugzilla prodsec bot auto closed it, thinking that this only affects community products. But, later, we added Red Hat Products which were affected by this CVE and the bug was reopened. And, for rhel distributions, yes fixes are in progress.
@trathi Any eta on this?
In reply to comment #21: > @trathi Any eta on this? Some updates for RHEL-8 will be out soon (By the end of this week or early next week).
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5361 https://access.redhat.com/errata/RHSA-2023:5361
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5363 https://access.redhat.com/errata/RHSA-2023:5363
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5360 https://access.redhat.com/errata/RHSA-2023:5360
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5362 https://access.redhat.com/errata/RHSA-2023:5362
Thanks for addressing this!
This issue has been addressed in the following products: NETWORK-OBSERVABILITY-1.4.0-RHEL-9 Via RHSA-2023:5379 https://access.redhat.com/errata/RHSA-2023:5379
@trathi The RedHat CVE report (https://access.redhat.com/security/cve/CVE-2022-25883) says this bug is fixed but when I look at the following images, the semver package is still vulnerable: $ docker run -it -u root --rm registry.access.redhat.com/ubi8/nodejs-16-minimal bash bash-4.4# cat /usr/lib/node_modules/npm/node_modules/semver/package.json | grep -A1 semver "name": "semver", "version": "7.3.7", $ docker run -it -u root --rm registry.access.redhat.com/ubi8/nodejs-18-minimal bash bash-4.4# cat /usr/lib/node_modules/npm/node_modules/semver/package.json | grep -A1 semver "name": "semver", "version": "7.5.1", It's the same for the node 16/18 UBI9 images as well.
I have also seen the semver at the levels above. Do we know when it will be fixed?
This issue has been addressed in the following products: EAP 7.4.13 Via RHSA-2023:5488 https://access.redhat.com/errata/RHSA-2023:5488
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2023:5484 https://access.redhat.com/errata/RHSA-2023:5484
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2023:5485 https://access.redhat.com/errata/RHSA-2023:5485
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2023:5486 https://access.redhat.com/errata/RHSA-2023:5486
@trathi any update on my comment above: https://bugzilla.redhat.com/show_bug.cgi?id=2216475#c29 ? The CVE https://access.redhat.com/security/cve/cve-2022-25883 says this is fixed in those images but the vulnerability is still showing up.
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2023:7222 https://access.redhat.com/errata/RHSA-2023:7222
This issue has been addressed in the following products: Migration Toolkit for Runtimes 1 on RHEL 8 Via RHSA-2024:0719 https://access.redhat.com/errata/RHSA-2024:0719
Marking EAP-8 as not affected because EAP 8 GA was released with the fixed version of nodejs-semver.