CVE-2021-33623
published 2021-05-28CVE-2021-33623: The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end()…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.90%
85.6th percentile
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-trim-newlines | < node-trim-newlines 3.0.0+~3.0.0-1 (bookworm) | node-trim-newlines 3.0.0+~3.0.0-1 (bookworm) |
| trim-newlines_project | trim-newlines | < 3.0.1 | 3.0.1 |
| trim-newlines_project | trim-newlines | >= 0 < 3.0.1 | 3.0.1 |
| trim-newlines_project | trim-newlines | >= 4.0.0 < 4.0.1 | 4.0.1 |
| trim-newlines_project | trim-newlines | >= 4.0.0 < 4.0.1 | 4.0.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
trim-newlines vulnerability
vendor_ubuntu·2023-04-05·CVSS 7.5
CVE-2021-33623 [HIGH] trim-newlines vulnerability
Title: trim-newlines vulnerability
Summary: A security issue was fixed in trim-newlines.
It was discovered that trim-newlines incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2021-33623)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nodejs-trim-newlines: ReDoS in .end() method
vendor_redhat·2021-05-28·CVSS 7.5
CVE-2021-33623 [HIGH] CWE-400 nodejs-trim-newlines: ReDoS in .end() method
nodejs-trim-newlines: ReDoS in .end() method
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
A flaw was found in nodejs-trim-newlines. Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
Statement: OpenShift Container Platform (OCP) grafana-container does package a vulnerable verison of nodejs trim-newlines. However due to the instance being read only and behind OpenShift OAuth, the impact by this vulnerability is Low. Red Hat Advanced Cluster Management for Kubernetes (ACM) containers affected by this flaw are only accessible to authenticated users, thus the impact of this vulnerability is Low.
Red Hat Virtualization (RHV) d
Debian
CVE-2021-33623: node-trim-newlines - The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an i...
vendor_debian·2021·CVSS 7.5
CVE-2021-33623 [HIGH] CVE-2021-33623: node-trim-newlines - The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an i...
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
Scope: local
bookworm: resolved (fixed in 3.0.0+~3.0.0-1)
bullseye: resolved (fixed in 3.0.0-1+deb11u1)
forky: resolved (fixed in 3.0.0+~3.0.0-1)
sid: resolved (fixed in 3.0.0+~3.0.0-1)
trixie: resolved (fixed in 3.0.0+~3.0.0-1)
OSV
node-trim-newlines vulnerability
osv·2023-04-05·CVSS 7.5
CVE-2021-33623 [HIGH] node-trim-newlines vulnerability
node-trim-newlines vulnerability
It was discovered that trim-newlines incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2021-33623)
OSV
Uncontrolled Resource Consumption in trim-newlines
osv·2021-06-07
CVE-2021-33623 [HIGH] Uncontrolled Resource Consumption in trim-newlines
Uncontrolled Resource Consumption in trim-newlines
@rkesters/gnuplot is an easy to use node module to draw charts using gnuplot and ps2pdf. The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the `.end()` method.
GHSA
Uncontrolled Resource Consumption in trim-newlines
ghsa·2021-06-07
CVE-2021-33623 [HIGH] CWE-400 Uncontrolled Resource Consumption in trim-newlines
Uncontrolled Resource Consumption in trim-newlines
@rkesters/gnuplot is an easy to use node module to draw charts using gnuplot and ps2pdf. The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the `.end()` method.
OSV
CVE-2021-33623: The trim-newlines package before 3
osv·2021-05-28·CVSS 7.5
CVE-2021-33623 [HIGH] CVE-2021-33623: The trim-newlines package before 3
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/sindresorhus/trim-newlines/releases/tag/v4.0.1https://lists.debian.org/debian-lts-announce/2022/12/msg00033.htmlhttps://security.netapp.com/advisory/ntap-20210702-0007/https://www.npmjs.com/package/trim-newlineshttps://github.com/sindresorhus/trim-newlines/releases/tag/v4.0.1https://lists.debian.org/debian-lts-announce/2022/12/msg00033.htmlhttps://security.netapp.com/advisory/ntap-20210702-0007/https://www.npmjs.com/package/trim-newlines
2021-05-28
Published