CVE-2017-1333
published 2017-11-01CVE-2017-1333: IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future…
PriorityP425medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.32%
67.7th percentile
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system. IBM X-Force ID: 126241.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debug_project | debug | >= 0 < 2.6.9 | 2.6.9 |
| debug_project | debug | >= 3.0.0 < 3.1.0 | 3.1.0 |
| garycourt | uri-js | >= 0 < 3.0.0 | 3.0.0 |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| ibm | openpages_grc_platform | — | — |
| juliangruber | brace-expansion | >= 0 < 1.1.7 | 1.1.7 |
| vercel | ms | >= 0 < 2.0.0 | 2.0.0 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
debug Inefficient Regular Expression Complexity vulnerability
ghsa·2023-01-09
CVE-2017-20165 [HIGH] CWE-1333 debug Inefficient Regular Expression Complexity vulnerability
debug Inefficient Regular Expression Complexity vulnerability
A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The name of the patch is c38a0166c266a679c8de012d4eaccec3f944e685. It is recommended to upgrade the affected component. The identifier VDB-217665 was assigned to this vulnerability. The patch has been backported to the 2.6.x branch in version 2.6.9.
GHSA
Vercel ms Inefficient Regular Expression Complexity vulnerability
ghsa·2023-01-05
CVE-2017-20162 [MEDIUM] CWE-1333 Vercel ms Inefficient Regular Expression Complexity vulnerability
Vercel ms Inefficient Regular Expression Complexity vulnerability
A vulnerability, which was classified as problematic, has been found in vercel ms up to 1.x. This issue affects the function parse of the file index.js. The manipulation of the argument str leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is caae2988ba2a37765d055c4eee63d383320ee662. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217451.
GHSA
GHSA-26f3-rpp2-39rf: IBM OpenPages GRC Platform 7
ghsa_unreviewed·2022-05-17
CVE-2017-1333 [MEDIUM] CWE-200 GHSA-26f3-rpp2-39rf: IBM OpenPages GRC Platform 7
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system. IBM X-Force ID: 126241.
GHSA
Regular Expression Denial Of Service in uri-js
ghsa·2018-07-24
CVE-2017-16021 [MEDIUM] CWE-1333 Regular Expression Denial Of Service in uri-js
Regular Expression Denial Of Service in uri-js
Affected versions of `uri-js` is susceptible to a regular expression denial of service vulnerability when user input is sent to the `.parse()` method.
## Recommendation
Update to v3.0.0 or later.
GHSA
ReDoS in brace-expansion
ghsa·2018-01-29
CVE-2017-18077 [HIGH] CWE-1333 ReDoS in brace-expansion
ReDoS in brace-expansion
Affected versions of `brace-expansion` are vulnerable to a regular expression denial of service condition.
## Proof of Concept
```
var expand = require('brace-expansion');
expand('{,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,\n}');
```
## Recommendation
Update to version 1.1.7 or later.
No detection rules found.
No writeups or analysis indexed.
http://www.ibm.com/support/docview.wss?uid=swg21997796http://www.securityfocus.com/bid/101656https://exchange.xforce.ibmcloud.com/vulnerabilities/126241http://www.ibm.com/support/docview.wss?uid=swg21997796http://www.securityfocus.com/bid/101656https://exchange.xforce.ibmcloud.com/vulnerabilities/126241
2017-11-01
Published