CVE-2021-3807
Aliases:GHSA-93q8-gq69-wqmw
Advisory lineage Upstream: 0 Downstream: 30
Modified
Published: 17 Sept 2021, 00:00
Last modified:03 Aug 2024, 17:09
Vulnerability Summary
Overall Risk (default)
medium
41/100 CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
0.21% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
17 Sept 2021, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 17:09
Last Modified
Vulnerability information updated
Description
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v3.0•HIGH•Score: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•HIGH•Score: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 0.21%• Percentile: 44%
Techniques & Countermeasures
- CWE-1333•Inefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
Affected Systems
- ansi-regex_project•ansi-regex
≥ 4.0.0, < 4.1.1 | 3.0.0 | 5.0.0 | 6.0.0
- chalk•chalk/ansi-regex
≥ unspecified, < 6.0.1 | ≥ unspecified, < 5.0.1
- Npm•ansi-regex
≥ 6.0.0, < 6.0.1 | ≥ 5.0.0, < 5.0.1 | ≥ 4.0.0, < 4.1.1 | ≥ 3.0.0, < 3.0.1
- oracle•communications_cloud_native_core_policy
1.15.0
References (14)
- https://huntr.dev/bounties/5b3cf33b-ede0-4398-9974-800876dfd994
- https://github.com/chalk/ansi-regex/commit/8d1d7cdb586269882c4bdc1b7325d0c58c8f76f9
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://security.netapp.com/advisory/ntap-20221014-0002/
- https://nvd.nist.gov/vuln/detail/CVE-2021-3807
- https://github.com/chalk/ansi-regex/issues/38#issuecomment-924086311
- https://github.com/chalk/ansi-regex/issues/38#issuecomment-925924774
- https://github.com/chalk/ansi-regex/commit/419250fa510bf31b4cc672e76537a64f9332e1f1
- https://github.com/chalk/ansi-regex/commit/75a657da7af875b2e2724fd6331bf0a4b23d3c9a
- https://github.com/chalk/ansi-regex/commit/c3c0b3f2736b9c01feec0fef33980c43720dcde8
- https://app.snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
- https://github.com/chalk/ansi-regex
- https://github.com/chalk/ansi-regex/releases/tag/v6.0.1
- https://security.netapp.com/advisory/ntap-20221014-0002