CVE-2021-3820
published 2021-09-27CVE-2021-3820: inflect is vulnerable to Inefficient Regular Expression Complexity
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.22%
67.4th percentile
inflect is vulnerable to Inefficient Regular Expression Complexity
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | i | >= 0 < 0.3.7 | 0.3.7 |
| inflect_project | inflect | < 0.3.7 | 0.3.7 |
| pksunkara | pksunkara_inflect | unspecified – 0.3.6 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
inflect vulnerable to Inefficient Regular Expression Complexity
osv·2021-09-29
CVE-2021-3820 [HIGH] inflect vulnerable to Inefficient Regular Expression Complexity
inflect vulnerable to Inefficient Regular Expression Complexity
inflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression Complexity
GHSA
inflect vulnerable to Inefficient Regular Expression Complexity
ghsa·2021-09-29
CVE-2021-3820 [HIGH] CWE-1333 inflect vulnerable to Inefficient Regular Expression Complexity
inflect vulnerable to Inefficient Regular Expression Complexity
inflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression Complexity
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-21671 jenkins: session fixation vulnerability
bugzilla·2021-09-24·CVSS 7.5
CVE-2021-21671 [HIGH] CVE-2021-21671 jenkins: session fixation vulnerability
CVE-2021-21671 jenkins: session fixation vulnerability
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
References:
https://www.jenkins.io/security/advisory/2021-06-30/#SECURITY-2371
http://www.openwall.com/lists/oss-security/2021/06/30/1
Discussion:
This vulnerability was introduced in Jenkins 2.266 and LTS 2.277.1.
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.8
Via RHSA-2021:3820 https://access.redhat.com/errata/RHSA-2021:3820
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2021-21671
Bugzilla
CVE-2021-21670 jenkins: improper permission checks allow canceling queue items and aborting builds
bugzilla·2021-09-24·CVSS 4.3
CVE-2021-21670 [MEDIUM] CVE-2021-21670 jenkins: improper permission checks allow canceling queue items and aborting builds
CVE-2021-21670 jenkins: improper permission checks allow canceling queue items and aborting builds
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.
References:
https://www.jenkins.io/security/advisory/2021-06-30/#SECURITY-2278
http://www.openwall.com/lists/oss-security/2021/06/30/1
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.8
Via RHSA-2021:3820 https://access.redhat.com/errata/RHSA-2021:3820
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2021-21670
2021-09-27
Published