CVE-2021-3749
published 2021-08-31CVE-2021-3749: axios is vulnerable to Inefficient Regular Expression Complexity
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
8.52%
94.4th percentile
axios is vulnerable to Inefficient Regular Expression Complexity
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axios | axios | <= 0.21.1 | — |
| axios | axios | >= 0 < 0.21.2 | 0.21.2 |
| axios | axios_axios | unspecified – 0.21.1 | — |
| debian | node-axios | < node-axios 0.21.3+dfsg-1 (bookworm) | node-axios 0.21.3+dfsg-1 (bookworm) |
| oracle | goldengate | >= 21.1 < 21.7.0.0.0 | 21.7.0.0.0 |
| siemens | sinec_ins | < 1.0 | 1.0 |
| siemens | sinec_ins | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Subnet Solutions Inc. PowerSYSTEM Center
cisa_ics·2024-10-03·CVSS 5.9
[MEDIUM] Subnet Solutions Inc. PowerSYSTEM Center
ICS Advisory
##
Subnet Solutions Inc. PowerSYSTEM Center
Release DateOctober 03, 2024
Alert CodeICSA-24-277-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Subnet Solutions Inc.
- Equipment: PowerSYSTEM Center
- Vulnerabilities: Server-Side Request Forgery (SSRF), Inefficient Regular Expression Complexity, Cross-Site Request Forgery (CSRF)
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in an attacker bypassing a proxy, creating a denial-of-service condition, or viewing sensitive information.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions
CISA ICS
Siemens SINEC INS
cisa_ics·2022-09-15·CVSS 7.8
[HIGH] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedSeptember 15, 2022
Alert CodeICSA-22-258-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Input Validation, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, Command Injection, Inadequate Encryption Strength, Missing Encryption of Sensitive Data, Improper Restriction of Operations Within the Bounds of a Memory Buffer, Exposure of Private Personal Information to an Unauthorized Actor, Open Redirect, Improper Resour
Oracle
Oracle Oracle GoldenGate Risk Matrix: Oracle GoldenGate (axios) — CVE-2021-3749
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-3749 [HIGH] Oracle Oracle GoldenGate Risk Matrix: Oracle GoldenGate (axios) — CVE-2021-3749
Oracle Oracle GoldenGate Risk Matrix: Oracle GoldenGate (axios) vulnerability
CVE: CVE-2021-3749
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
nodejs-axios: Regular expression denial of service in trim function
vendor_redhat·2021-08-31·CVSS 7.5
CVE-2021-3749 [HIGH] CWE-400 nodejs-axios: Regular expression denial of service in trim function
nodejs-axios: Regular expression denial of service in trim function
axios is vulnerable to Inefficient Regular Expression Complexity
A Regular Expression Denial of Service (ReDoS) vulnerability was found in the nodejs axios. This flaw allows an attacker to provide crafted input to the trim function, which might cause high resources consumption and as a consequence lead to denial of service. The highest threat from this vulnerability is system availability.
Statement: * OpenShift Container Platform (OCP) grafana-container does package a vulnerable version of nodejs axios. However, due to the instance being read only and behind OpenShift OAuth, the impact of this vulnerability is Low.
* Red Hat Advanced Cluster Management for Kubernetes (RHACM) 2.1 and previous versions does contain a vul
Debian
CVE-2021-3749: node-axios - axios is vulnerable to Inefficient Regular Expression Complexity
vendor_debian·2021·CVSS 7.5
CVE-2021-3749 [HIGH] CVE-2021-3749: node-axios - axios is vulnerable to Inefficient Regular Expression Complexity
axios is vulnerable to Inefficient Regular Expression Complexity
Scope: local
bookworm: resolved (fixed in 0.21.3+dfsg-1)
bullseye: resolved (fixed in 0.21.1+dfsg-1+deb11u1)
forky: resolved (fixed in 0.21.3+dfsg-1)
sid: resolved (fixed in 0.21.3+dfsg-1)
trixie: resolved (fixed in 0.21.3+dfsg-1)
OSV
axios Inefficient Regular Expression Complexity vulnerability
osv·2021-09-01
CVE-2021-3749 [HIGH] axios Inefficient Regular Expression Complexity vulnerability
axios Inefficient Regular Expression Complexity vulnerability
axios before v0.21.2 is vulnerable to Inefficient Regular Expression Complexity.
GHSA
axios Inefficient Regular Expression Complexity vulnerability
ghsa·2021-09-01
CVE-2021-3749 [HIGH] CWE-1333 axios Inefficient Regular Expression Complexity vulnerability
axios Inefficient Regular Expression Complexity vulnerability
axios before v0.21.2 is vulnerable to Inefficient Regular Expression Complexity.
OSV
CVE-2021-3749: axios is vulnerable to Inefficient Regular Expression Complexity
osv·2021-08-31·CVSS 7.5
CVE-2021-3749 [HIGH] CVE-2021-3749: axios is vulnerable to Inefficient Regular Expression Complexity
axios is vulnerable to Inefficient Regular Expression Complexity
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/axios/axios/commit/5b457116e31db0e88fede6c428e969e87f290929https://huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31https://lists.apache.org/thread.html/r075d464dce95cd13c03ff9384658edcccd5ab2983b82bfc72b62bb10%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r216f0fd0a3833856d6a6a1fada488cadba45f447d87010024328ccf2%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r3ae6d2654f92c5851bdb73b35e96b0e4e3da39f28ac7a1b15ae3aab8%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r4bf1b32983f50be00f9752214c1b53738b621be1c2b0dbd68c7f2391%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r7324ecc35b8027a51cb6ed629490fcd3b2d7cf01c424746ed5744bf1%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r74d0b359408fff31f87445261f0ee13bdfcac7d66f6b8e846face321%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/ra15d63c54dc6474b29f72ae4324bcb03038758545b3ab800845de7a1%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc263bfc5b53afcb7e849605478d73f5556eb0c00d1f912084e407289%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rfa094029c959da0f7c8cd7dc9c4e59d21b03457bf0cedf6c93e1bb0a%40%3Cdev.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rfc5c478053ff808671aef170f3d9fc9d05cc1fab8fb64431edc66103%40%3Ccommits.druid.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/axios/axios/commit/5b457116e31db0e88fede6c428e969e87f290929https://huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31https://lists.apache.org/thread.html/r075d464dce95cd13c03ff9384658edcccd5ab2983b82bfc72b62bb10%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r216f0fd0a3833856d6a6a1fada488cadba45f447d87010024328ccf2%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r3ae6d2654f92c5851bdb73b35e96b0e4e3da39f28ac7a1b15ae3aab8%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r4bf1b32983f50be00f9752214c1b53738b621be1c2b0dbd68c7f2391%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r7324ecc35b8027a51cb6ed629490fcd3b2d7cf01c424746ed5744bf1%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r74d0b359408fff31f87445261f0ee13bdfcac7d66f6b8e846face321%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/ra15d63c54dc6474b29f72ae4324bcb03038758545b3ab800845de7a1%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc263bfc5b53afcb7e849605478d73f5556eb0c00d1f912084e407289%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rfa094029c959da0f7c8cd7dc9c4e59d21b03457bf0cedf6c93e1bb0a%40%3Cdev.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rfc5c478053ff808671aef170f3d9fc9d05cc1fab8fb64431edc66103%40%3Ccommits.druid.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2022.html
2021-08-31
Published