CVE-2021-3807

Aliases:GHSA-93q8-gq69-wqmw
Modified
Published: 17 Sept 2021, 00:00
Last modified:03 Aug 2024, 17:09

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
0.21% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

17 Sept 2021, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 17:09
Last Modified
Vulnerability information updated

Description

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.21% Percentile: 44%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • ansi-regex_projectansi-regex

    ≥ 4.0.0, < 4.1.1 | 3.0.0 | 5.0.0 | 6.0.0

  • chalkchalk/ansi-regex

    ≥ unspecified, < 6.0.1 | ≥ unspecified, < 5.0.1

  • Npmansi-regex

    ≥ 6.0.0, < 6.0.1 | ≥ 5.0.0, < 5.0.1 | ≥ 4.0.0, < 4.1.1 | ≥ 3.0.0, < 3.0.1

  • oraclecommunications_cloud_native_core_policy

    1.15.0

References (14)