CVE-2022-38900
published 2023-02-08CVE-2022-38900: A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
23.79%
97.7th percentile
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | — | — |
| decode-uri-component_project | decode-uri-component | < 0.2.1 | 0.2.1 |
| decode-uri-component_project | decode-uri-component | — | — |
| decode-uri-component_project | decode-uri-component | >= 0 < 0.2.1 | 0.2.1 |
| elastic | kibana | — | — |
| elastic | kibana | >= 7.0.0 < 7.17.9 | 7.17.9 |
| elastic | kibana | >= 8.0.0 < 8.6.1 | 8.6.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ph5g-2r58-hm46: A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that c
ghsa_unreviewed·2023-07-06·CVSS 7.5
CVE-2022-38778 [HIGH] CWE-20 GHSA-ph5g-2r58-hm46: A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that c
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
OSV
decode-uri-component vulnerable to Denial of Service (DoS)
osv·2022-11-28
CVE-2022-38900 [HIGH] decode-uri-component vulnerable to Denial of Service (DoS)
decode-uri-component vulnerable to Denial of Service (DoS)
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
GHSA
decode-uri-component vulnerable to Denial of Service (DoS)
ghsa·2022-11-28
CVE-2022-38900 [HIGH] CWE-20 decode-uri-component vulnerable to Denial of Service (DoS)
decode-uri-component vulnerable to Denial of Service (DoS)
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
Atlassian
CVE-2022-38900: DoS (Denial of Service) decode-uri-component Dependency in Confluence Data Center
vendor_atlassian·2024-11-19·CVSS 7.5
CVE-2022-38900 [HIGH] CVE-2022-38900: DoS (Denial of Service) decode-uri-component Dependency in Confluence Data Center
CVE-2022-38900: DoS (Denial of Service) decode-uri-component Dependency in Confluence Data Center
DoS (Denial of Service) decode-uri-component Dependency in Confluence Data Center
CVE: CVE-2022-38900
Affected products: Confluence Data Center
Red Hat
kibana: Kibana authenticated Denial of Service issue (ESA-2023-02)
vendor_redhat·2023-02-08·CVSS 6.5
CVE-2022-38778 [MEDIUM] CWE-20 kibana: Kibana authenticated Denial of Service issue (ESA-2023-02)
kibana: Kibana authenticated Denial of Service issue (ESA-2023-02)
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
A flaw was found in one of Kibana’s third-party dependencies. This issue could allow an authenticated user to perform a request that crashes the Kibana server process.
Package: openshift-logging/cluster-logging-rhel9-operator (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: openshift-logging/elasticsearch-rhel8-operator (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: openshift-logging/kibana6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: kibana (Red Hat JBoss Fuse 6) - Out of s
Red Hat
decode-uri-component: improper input validation resulting in DoS
vendor_redhat·2022-11-28·CVSS 7.5
CVE-2022-38900 [HIGH] CWE-20 decode-uri-component: improper input validation resulting in DoS
decode-uri-component: improper input validation resulting in DoS
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
A flaw was found in decode-uri-component. This issue occurs due to a specially crafted input, resulting in a denial of service.
Statement: For OpenShift Container Platform (OCP), Advanced Clusters Management for Kubernetes (ACM) and Advanced Cluster Security (ACS), the NPM decode-uri-component package is only present in source repositories as a development dependency, it is not used in production. Therefore this vulnerability is rated Low for OCP and ACS.
In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container bundles many nodejs packages as a build time dependencies, including the decode-uri-component package.
The vu
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-38900 yarnpkg: decode-uri-component: improper input validation resulting in DoS [epel-8]
bugzilla·2023-07-12·CVSS 7.5
CVE-2022-38900 [HIGH] CVE-2022-38900 yarnpkg: decode-uri-component: improper input validation resulting in DoS [epel-8]
CVE-2022-38900 yarnpkg: decode-uri-component: improper input validation resulting in DoS [epel-8]
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2170644
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=securit
Bugzilla
CVE-2022-38900 decode-uri-component: improper input validation resulting in DoS
bugzilla·2023-02-16·CVSS 7.5
CVE-2022-38900 [HIGH] CVE-2022-38900 decode-uri-component: improper input validation resulting in DoS
CVE-2022-38900 decode-uri-component: improper input validation resulting in DoS
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
https://github.com/SamVerschueren/decode-uri-component/issues/5
Discussion:
Created cockatrice tracking bugs for this issue:
Affects: fedora-36 [bug 2170652]
Created golang-entgo-ent tracking bugs for this issue:
Affects: fedora-36 [bug 2170653]
Created golang-github-prometheus tracking bugs for this issue:
Affects: epel-7 [bug 2170649]
Created grafana tracking bugs for this issue:
Affects: fedora-36 [bug 2170654]
Created mozjs68 tracking bugs for this issue:
Affects: fedora-36 [bug 2170655]
Created mozjs78 tracking bugs for this issue:
Affects: fedora-36 [bug 2170656]
Created nodejs:13/nodejs tracking
2023-02-08
Published