CVE-2021-3807

Aliases:GHSA-93q8-gq69-wqmwDEBIAN-CVE-2021-3807CGA-5x7f-x695-2x67CGA-9v9h-gg3x-r6fqCGA-fr92-2hq2-qv4hCGA-gw4x-p4mc-4gfc
Modified
Published: 17 Sept 2021, 00:00
Last modified:03 Aug 2024, 17:09

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
3.55% LOW
4% probability +3.34%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

17 Sept 2021, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 17:09
Last Modified
Vulnerability information updated

Description

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 3.55% Percentile: 89%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • ansi-regex_projectansi-regex

    ≥ 4.0.0, < 4.1.1 | 3.0.0 | 5.0.0 | 6.0.0

  • chainguardarangodb-3.11

    all | < 3.11.14.5-r21

  • chainguardarangodb-3.12

    < 3.12.9.4-r17

  • chalkchalk/ansi-regex

    ≥ unspecified, < 6.0.1 | ≥ unspecified, < 5.0.1

  • debiannode-ansi-regex

    < 5.0.1-1~deb11u1 | < 5.0.1-1 | < 5.0.1-1 | < 5.0.1-1

  • Npmansi-regex

    ≥ 6.0.0, < 6.0.1 | ≥ 5.0.0, < 5.0.1 | ≥ 4.0.0, < 4.1.1 | ≥ 3.0.0, < 3.0.1

  • oraclecommunications_cloud_native_core_policy

    1.15.0

References (15)