CVE-2021-3807
🟡 Monitoruj
Ineffektywna złożoność wyrażenia regularnego w ansi-regex prowadzi do ataków typu Denial of Service.
CVSS
7.5
EPSS
3.5%
Exploit
poc
Vendor
ansi-regex_project
Opis źródłowy (NVD)
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 3.5% |
| Opublikowano (NVD) | 2021-09-17 07:15:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:11 UTC |
Referencje
- https://github.com/chalk/ansi-regex/commit/8d1d7cdb586269882c4bdc1b7325d0c58c8f76f9 ([email protected]) [Patch, Third Party Advisory]
- https://huntr.dev/bounties/5b3cf33b-ede0-4398-9974-800876dfd994 ([email protected]) [Exploit, Issue Tracking, Patch, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20221014-0002/ ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuapr2022.html ([email protected]) [Patch, Third Party Advisory]