CVE-2021-3810
published 2021-09-17CVE-2021-3810: code-server is vulnerable to Inefficient Regular Expression Complexity
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.22%
65.0th percentile
code-server is vulnerable to Inefficient Regular Expression Complexity
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cdr | cdr_code-server | >= unspecified < 3.12.0 | 3.12.0 |
| coder | code-server | < 3.12.0 | 3.12.0 |
| coder | code-server | >= 0 < 3.12.0 | 3.12.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Inefficient Regular Expression Complexity in code-server
ghsa·2021-09-20
CVE-2021-3810 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in code-server
Inefficient Regular Expression Complexity in code-server
code-server is vulnerable to Inefficient Regular Expression Complexity
OSV
Inefficient Regular Expression Complexity in code-server
osv·2021-09-20
CVE-2021-3810 [HIGH] Inefficient Regular Expression Complexity in code-server
Inefficient Regular Expression Complexity in code-server
code-server is vulnerable to Inefficient Regular Expression Complexity
Suricata
ET EXPLOIT Smart Google Code Inserter < 3.5 Auth Bypass (CVE-2018-3810)
suricata·2021-08-02·CVSS 9.8
CVE-2018-3810 [CRITICAL] ET EXPLOIT Smart Google Code Inserter < 3.5 Auth Bypass (CVE-2018-3810)
ET EXPLOIT Smart Google Code Inserter [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Smart Google Code Inserter < 3.5 Auth Bypass (CVE-2018-3810)"; flow:established,to_server; http.method; content:"POST"; nocase; http.uri; content:"/options-general.php?page=smartcode"; nocase; endswith; fast_pattern; http.request_body; content:"sgcgoogleanalytic="; nocase; startswith; content:"<script"; nocase; distance:0; content:"savegooglecode"; nocase; reference:url,www.exploit-db.com/exploits/43420; reference:url,github.com/projectdiscovery/nuclei; reference:cve,2018-3810; classtype:attempted-admin; sid:2033637; rev:2; metadata:affected_product Wordpress_Plugins, attack_target Web_Server, created_at 2021_08_02, cve CVE_2018_3810, deployment Perimeter, deployment SSLDecrypt, confidence High, signature_
No writeups or analysis indexed.
2021-09-17
Published