Regular Expression Denial of Service (ReDoS)
Published Oct 27, 2020
7.5
HIGHCVSS 3.1
EPSS 3.48%
Description
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
Affected products
- Vendor n/a Product Npm-User-Validate Defaultn/a
- Version unspecifiedStatusaffectedConstraints<1.0.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Npm-User-Validate | n/a |
|
- < 1.0.1
No data.
Red Hat Enterprise Linux 8
nodejs:10-8030020210118191659.229f0a1c
Fixed · RHSA-2021:0548
Red Hat Enterprise Linux 8
nodejs:12-8030020210129141730.229f0a1c
Fixed · RHSA-2021:0549
Red Hat Enterprise Linux 8
nodejs:14-8030020210126165503.229f0a1c
Fixed · RHSA-2021:0551
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.20.1-1.el7
Fixed · RHSA-2021:0485
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-nodemon-0:2.0.3-1.el7
Fixed · RHSA-2021:0485
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.20.1-1.el7
Fixed · RHSA-2021:0485
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-nodemon-0:2.0.3-1.el7
Fixed · RHSA-2021:0485
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.20.1-1.el7
Fixed · RHSA-2021:0485
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-nodemon-0:2.0.3-1.el7
Fixed · RHSA-2021:0485
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Red Hat OpenShift Container Platform 3.11
kibana
Fix deferred
Red Hat OpenShift Container Platform 4
kibana
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:10-8030020210118191659.229f0a1c | Fixed | RHSA-2021:0548 |
| Red Hat Enterprise Linux 8 | nodejs:12-8030020210129141730.229f0a1c | Fixed | RHSA-2021:0549 |
| Red Hat Enterprise Linux 8 | nodejs:14-8030020210126165503.229f0a1c | Fixed | RHSA-2021:0551 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.20.1-1.el7 | Fixed | RHSA-2021:0485 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-nodemon-0:2.0.3-1.el7 | Fixed | RHSA-2021:0485 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.20.1-1.el7 | Fixed | RHSA-2021:0485 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-nodemon-0:2.0.3-1.el7 | Fixed | RHSA-2021:0485 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.20.1-1.el7 | Fixed | RHSA-2021:0485 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-nodemon-0:2.0.3-1.el7 | Fixed | RHSA-2021:0485 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Red Hat OpenShift Container Platform 3.11 | kibana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
npm-user-validate
npm
Introduced 0 Fixed 1.0.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | npm-user-validate | 0 | 1.0.1 |
Remediation
Red Hat statement
In Red Hat Enterprise Linux 8 and Software Collections, `npm-user-validate` is used exclusively for `npm`. As a result, this vulnerability is considered Low in such a context. In OpenShift Container Platform (OCP) 3.11 and 4.4 the kibana package has been marked Low (similar to RHEL8) as it is primarily used for npm and is protected via OpenShift OAuth. Additionally, whilst OCP 4.4 does deliver the kibana package, due to the code changing to container first content, it has been marked as wontfix at this time and may be fixed in a future release. Additionally, the openshift4/ose-logging-kibana6 container is not represented on the CVE page as it gets npm from the Red Hat Software Collections and as such the ose-logging-kibana6 container will be updated when the rh-nodejs10-nodejs package is.
References (9)
- https://access.redhat.com/security/cve/CVE-2020-7754 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1892430 Issue Tracking
- https://github.com/advisories/GHSA-pw54-mh39-w3hc Advisory
- https://github.com/npm/npm-user-validate/commit/c8a87dac1a4cc6988b5418f30411a8669bef204e x_refsource_MISCPatchThird Party Advisory
- https://github.com/npm/npm-user-validate/security/advisories/GHSA-xgh6-85xh-479p x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7754
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1019353 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-NPMUSERVALIDATE-1019352 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7754
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7754 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1892430 | Issue Tracking | |
| https://github.com/advisories/GHSA-pw54-mh39-w3hc | Advisory | |
| https://github.com/npm/npm-user-validate/commit/c8a87dac1a4cc6988b5418f30411a8669bef204e | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/npm/npm-user-validate/security/advisories/GHSA-xgh6-85xh-479p | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7754 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1019353 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-NPMUSERVALIDATE-1019352 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7754 |
Change history (0)
No recorded changes yet.