Regular Expression Denial of Service (ReDoS)
Published Dec 11, 2020
7.5
HIGHCVSS 3.1
EPSS 3.92%
Description
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
Affected products
- Vendor n/a Product UA-Parser-JS Defaultn/a
- Version unspecifiedStatusaffectedConstraints<0.7.23
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | UA-Parser-JS | n/a |
|
Configuration 1
- < 0.7.23
No data.
Distributed Tracing Jaeger 1
distributed-tracing/jaeger-all-in-one-rhel7
Out of support scope
Distributed Tracing Jaeger 1
distributed-tracing/jaeger-query-rhel7
Out of support scope
OpenShift Service Mesh 1
servicemesh-grafana
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
nodejs-ua-parser-js
Fix deferred
Red Hat Ceph Storage 3
grafana
Not affected
Red Hat Ceph Storage 3
grafana-container
Fix deferred
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Not affected
Red Hat OpenShift Container Platform 3.11
kibana
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Not affected
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Fix deferred
Red Hat Storage 3
grafana
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-all-in-one-rhel7 | Out of support scope | n/a |
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-query-rhel7 | Out of support scope | n/a |
| OpenShift Service Mesh 1 | servicemesh-grafana | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | nodejs-ua-parser-js | Fix deferred | n/a |
| Red Hat Ceph Storage 3 | grafana | Not affected | n/a |
| Red Hat Ceph Storage 3 | grafana-container | Fix deferred | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Fix deferred | n/a |
| Red Hat Storage 3 | grafana | Fix deferred | n/a |
ua-parser-js
npm
Introduced 0 Fixed 0.7.23
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | ua-parser-js | 0 | 0.7.23 |
Remediation
Red Hat statement
Red Hat OpenShift Container Platform 4 delivers the kibana package where the ua-parser-js library is bundled, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future. Red Hat Ceph Storage 3 and 4 ship a version of grafana that pulls a version of ua-parser-js (0.7.9) that uses the affected code.
References (11)
- https://access.redhat.com/security/cve/CVE-2020-7793 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1907451 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf x_refsource_CONFIRMThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0786 Advisory
- https://github.com/advisories/GHSA-394c-5j6w-4xmx Advisory
- https://github.com/faisalman/ua-parser-js/commit/6d1f26df051ba681463ef109d36c9cf0f7e32b18 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7793
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-1050388 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050387 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7793
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7793 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1907451 | Issue Tracking | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf | x_refsource_CONFIRMThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0786 | Advisory | |
| https://github.com/advisories/GHSA-394c-5j6w-4xmx | Advisory | |
| https://github.com/faisalman/ua-parser-js/commit/6d1f26df051ba681463ef109d36c9cf0f7e32b18 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7793 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-1050388 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050387 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7793 |
Change history (0)
No recorded changes yet.