Uploaded image for project: 'Migration Toolkit for Applications'
  1. Migration Toolkit for Applications
  2. MTA-80

CVE-2021-35065 mta-ui-container: glob-parent: Regular Expression Denial of Service [mta-6]

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • QE - Ack
    • None

      Security Tracking Issue

      Do not make this issue public.

      Impact: Moderate
      Reported Date: 26-Dec-2022
      PM Fix/Wontfix Decision By: 27-Jan-2023
      Resolve Bug By: 24-Jun-2023

      In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this bug.

      Please review this tracker and its impact on your product or service, as soon as possible. The trackers are filed WITHOUT in-depth analysis as the vulnerability has a Low or Moderate severity impact on this product or service. For more details, please refer to following confluence page - https://docs.engineering.redhat.com/x/3e_3EQ

      Please see the Security Errata Policy for further details: https://docs.engineering.redhat.com/x/9kKpDw

      Flaw:


      CVE-2021-35065 glob-parent: Regular Expression Denial of Service
      https://bugzilla.redhat.com/show_bug.cgi?id=2156324

      The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

      https://github.com/gulpjs/glob-parent/commit/3e9f04a3b4349db7e1962d87c9a7398cda51f339
      https://github.com/gulpjs/glob-parent/pull/49
      https://security.snyk.io/vuln/SNYK-JS-GLOBPARENT-1314294

              ibolton@redhat.com Ian Bolton
              ahanwate1@redhat.com Avinash Hanwate
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: