CVE-2021-3801

Related Vulnerabilities: CVE-2021-3801  

prism is vulnerable to Inefficient Regular Expression Complexity

Description

The MITRE CVE dictionary describes this issue as:

prism is vulnerable to Inefficient Regular Expression Complexity

Statement

OpenShift Container Platform (OCP) grafana-container does package a vulnerable verison of prismjs. However due to the instance being read only and behind OpenShift OAuth, it has been given a Low impact. Additionally it has been marked as wont-fix at this time and may be fixed in a future release.

OpenShift Container Platform (OCP) grafana-container does package a vulnerable verison of prismjs. However due to the instance being read only and behind OpenShift OAuth, it has been given a Low impact. Additionally it has been marked as wont-fix at this time and may be fixed in a future release.

Additional Information

  • Bugzilla 2005445: CVE-2021-3801 nodejs-prismjs: ReDoS vulnerability
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-3801