CVE-2021-3807

Related Vulnerabilities: CVE-2021-3807  

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

Description

The MITRE CVE dictionary describes this issue as:

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

Statement

In Red Hat Virtualization and Red Hat Quay some components use a vulnerable version of ansi-regex. However, all frontend code is executed on the client side. As the maximum impact of this vulnerability is denial of service in the client, the vulnerability is rated Moderate for those products.

In Red Hat Virtualization and Red Hat Quay some components use a vulnerable version of ansi-regex. However, all frontend code is executed on the client side. As the maximum impact of this vulnerability is denial of service in the client, the vulnerability is rated Moderate for those products.

Additional Information

  • Bugzilla 2007557: CVE-2021-3807 node-ansi-regex: inefficient regular expression complexity allows for a crash
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-3807