CVE-2021-27290
published 2021-03-12CVE-2021-27290: ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.72%
90.8th percentile
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-ssri | < node-ssri 8.0.1-1 (bookworm) | node-ssri 8.0.1-1 (bookworm) |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | 1.0.1.1 |
| ssri_project | ssri | >= 5.2.2 < 6.0.2 | 6.0.2 |
| ssri_project | ssri | >= 5.2.2 < 6.0.2 | 6.0.2 |
| ssri_project | ssri | >= 7.0.0 < 8.0.1 | 8.0.1 |
| ssri_project | ssri | >= 7.0.0 < 7.1.1 | 7.1.1 |
| ssri_project | ssri | >= 8.0.0 < 8.0.1 | 8.0.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2021-27290
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2021-27290 [HIGH] Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2021-27290
Oracle Oracle Java SE Risk Matrix: Node (Node.js) vulnerability
CVE: CVE-2021-27290
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode
vendor_redhat·2021-03-12·CVSS 7.5
CVE-2021-27290 [HIGH] CWE-770 nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode
nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
A flaw was found in ssri package. A malicious string provided by an attacker may lead to Regular Expression Denial of Service (ReDoS). This issue only affects consumers
using the strict option. The highest threat from this vulnerability is to availability.
Statement: Whilst the OpenShift ServiceMesh (OSSM) servicemesh-grafana and servicemesh-prometheus include the vulnerable ssri library, the vulnerable "strict" option is not used. Simil
Debian
CVE-2021-27290: node-ssri - ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression whic...
vendor_debian·2021·CVSS 7.5
CVE-2021-27290 [HIGH] CVE-2021-27290: node-ssri - ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression whic...
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Scope: local
bookworm: resolved (fixed in 8.0.1-1)
bullseye: resolved (fixed in 8.0.1-1)
forky: resolved (fixed in 8.0.1-1)
sid: resolved (fixed in 8.0.1-1)
trixie: resolved (fixed in 8.0.1-1)
GHSA
Regular Expression Denial of Service (ReDoS)
ghsa·2021-03-19
CVE-2021-27290 [HIGH] CWE-400 Regular Expression Denial of Service (ReDoS)
Regular Expression Denial of Service (ReDoS)
npm `ssri` 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
OSV
Regular Expression Denial of Service (ReDoS)
osv·2021-03-19
CVE-2021-27290 [HIGH] Regular Expression Denial of Service (ReDoS)
Regular Expression Denial of Service (ReDoS)
npm `ssri` 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
OSV
CVE-2021-27290: ssri 5
osv·2021-03-12·CVSS 7.5
CVE-2021-27290 [HIGH] CVE-2021-27290: ssri 5
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdfhttps://github.com/yetingli/SaveResults/blob/main/pdf/ssri-redos.pdfhttps://npmjs.comhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdfhttps://github.com/yetingli/SaveResults/blob/main/pdf/ssri-redos.pdfhttps://npmjs.comhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-12
Published