CVE-2021-3795

Related Vulnerabilities: CVE-2021-3795  

semver-regex is vulnerable to Inefficient Regular Expression Complexity

Description

The MITRE CVE dictionary describes this issue as:

semver-regex is vulnerable to Inefficient Regular Expression Complexity

Statement

The Red Hat Directory Server 11 Web UI semver-regex as a dependency, but it is not used in the 389-ds cockpit plugin, and not shipped as part of the RPM binary. Thus Red Hat Directory Server 11 is not affected by this flaw.

The Red Hat Directory Server 11 Web UI semver-regex as a dependency, but it is not used in the 389-ds cockpit plugin, and not shipped as part of the RPM binary. Thus Red Hat Directory Server 11 is not affected by this flaw.

Additional Information

  • Bugzilla 2006009: CVE-2021-3795 semver-regex: inefficient regular expression complexity
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-3795