CVE-2021-23362
published 2021-03-23CVE-2021-23362: The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
3.61%
88.2th percentile
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-hosted-git-info | < node-hosted-git-info 3.0.8-1 (bookworm) | node-hosted-git-info 3.0.8-1 (bookworm) |
| npmjs | hosted-git-info | >= 0 < 2.8.9 | 2.8.9 |
| npmjs | hosted-git-info | >= 2.0.0 < 2.8.9 | 2.8.9 |
| npmjs | hosted-git-info | >= 3.0.0 < 3.0.8 | 3.0.8 |
| npmjs | hosted-git-info | >= 3.0.0 < 3.0.8 | 3.0.8 |
| npmjs | hosted-git-info | >= unspecified < 3.0.8 | 3.0.8 |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | 1.0.1.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Regular Expression Denial of Service in hosted-git-info
osv·2021-05-06
CVE-2021-23362 [MEDIUM] Regular Expression Denial of Service in hosted-git-info
Regular Expression Denial of Service in hosted-git-info
The npm package `hosted-git-info` before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity
GHSA
Regular Expression Denial of Service in hosted-git-info
ghsa·2021-05-06
CVE-2021-23362 [MEDIUM] CWE-400 Regular Expression Denial of Service in hosted-git-info
Regular Expression Denial of Service in hosted-git-info
The npm package `hosted-git-info` before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity
OSV
CVE-2021-23362: The package hosted-git-info before 3
osv·2021-03-23·CVSS 5.3
CVE-2021-23362 [MEDIUM] CVE-2021-23362: The package hosted-git-info before 3
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
Ubuntu
hosted-git-info vulnerability
vendor_ubuntu·2022-09-02
CVE-2021-23362 hosted-git-info vulnerability
Title: hosted-git-info vulnerability
Summary: hosted-git-info could be made to crash if it received specially crafted
input.
It was discovered that hosted-git-info incorrectly handled certain inputs. A
remote attacker could use this to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Red Hat
nodejs-hosted-git-info: Regular Expression denial of service via shortcutMatch in fromUrl()
vendor_redhat·2021-03-23·CVSS 5.3
CVE-2021-23362 [MEDIUM] CWE-400 nodejs-hosted-git-info: Regular Expression denial of service via shortcutMatch in fromUrl()
nodejs-hosted-git-info: Regular Expression denial of service via shortcutMatch in fromUrl()
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
A regular expression denial of service vulnerability was found in hosted-git-info. If an application allows user input into the affected regular expression (regexp) function, `shortcutMatch` or `fromUrl`, then an attacker could craft a regexp which takes an ever increasing amount of time to process, potentially resulting in a denial of service.
Statement: While some components do package a vulnerable version of hosted-git-info, access to them
Debian
CVE-2021-23362: node-hosted-git-info - The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression De...
vendor_debian·2021·CVSS 5.3
CVE-2021-23362 [MEDIUM] CVE-2021-23362: node-hosted-git-info - The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression De...
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
Scope: local
bookworm: resolved (fixed in 3.0.8-1)
bullseye: resolved (fixed in 3.0.8-1)
forky: resolved (fixed in 3.0.8-1)
sid: resolved (fixed in 3.0.8-1)
trixie: resolved (fixed in 3.0.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://github.com/npm/hosted-git-info/commit/29adfe5ef789784c861b2cdeb15051ec2ba651a7https://github.com/npm/hosted-git-info/commit/8d4b3697d79bcd89cdb36d1db165e3696c783a01https://github.com/npm/hosted-git-info/commit/bede0dc38e1785e732bf0a48ba6f81a4a908eba3https://github.com/npm/hosted-git-info/commits/v2https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1088356https://snyk.io/vuln/SNYK-JS-HOSTEDGITINFO-1088355https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://github.com/npm/hosted-git-info/commit/29adfe5ef789784c861b2cdeb15051ec2ba651a7https://github.com/npm/hosted-git-info/commit/8d4b3697d79bcd89cdb36d1db165e3696c783a01https://github.com/npm/hosted-git-info/commit/bede0dc38e1785e732bf0a48ba6f81a4a908eba3https://github.com/npm/hosted-git-info/commits/v2https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1088356https://snyk.io/vuln/SNYK-JS-HOSTEDGITINFO-1088355
2021-03-23
Published