7.8
CVSSv2

CVE-2021-3749

Published: 31/08/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 695
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

axios is vulnerable to Inefficient Regular Expression Complexity

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

axios axios

siemens sinec ins 1.0

siemens sinec ins

oracle goldengate

Vendor Advisories

Synopsis Important: Red Hat OpenShift Service Mesh 209 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Service Mesh 209Red Hat Product Security has rated this update as having a secu ...
Synopsis Moderate: OpenShift Container Platform 4103 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4103 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...

ICS Advisories

Github Repositories

A NodeRed node to execute GraphQL Queries

node-red-contrib-graphql A NodeRed node to execute GraphQL Queries Change Log Vers Changes 212 Fix payload init issue 210 Bearer Token Authentication 201 Update dependencies (axios & mustache), fix node-red scorecard issues 200 GraphQL response is now on payloadgraphql instead of replacing payload This is a breaking change Addresses #32 1

Axios Redos (CVE-2021-3749) proof of concept

Axios Regular Expression Denial Of Service Attack This repo hold a POC of CVE-2021-3749 Overview A ReDoS (regular expression denial of service) flaw was found in the axios package An attacker that is able to provide crafted input to the trim function may cause an application to consume an excessive amount of CPU Fix Commit: githubcom/axios/axios/commit/5b457116e31d

EVER Wallet browser extension

EVER Wallet A browser extension to manage Everscale wallets and access dApps directly from your browser How to build # Prepare builder container docker build --tag ever-wallet-extension # Build extension docker run -ti --rm --mount type=bind,source=$(pwd),target=/app ever-wallet-extension # Extens

References

CWE-1333https://github.com/axios/axios/commit/5b457116e31db0e88fede6c428e969e87f290929https://huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://lists.apache.org/thread.html/r7324ecc35b8027a51cb6ed629490fcd3b2d7cf01c424746ed5744bf1%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rfc5c478053ff808671aef170f3d9fc9d05cc1fab8fb64431edc66103%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r216f0fd0a3833856d6a6a1fada488cadba45f447d87010024328ccf2%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r3ae6d2654f92c5851bdb73b35e96b0e4e3da39f28ac7a1b15ae3aab8%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/ra15d63c54dc6474b29f72ae4324bcb03038758545b3ab800845de7a1%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r74d0b359408fff31f87445261f0ee13bdfcac7d66f6b8e846face321%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc263bfc5b53afcb7e849605478d73f5556eb0c00d1f912084e407289%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r4bf1b32983f50be00f9752214c1b53738b621be1c2b0dbd68c7f2391%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r075d464dce95cd13c03ff9384658edcccd5ab2983b82bfc72b62bb10%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rfa094029c959da0f7c8cd7dc9c4e59d21b03457bf0cedf6c93e1bb0a%40%3Cdev.druid.apache.org%3Ehttps://access.redhat.com/errata/RHSA-2022:1276https://nvd.nist.govhttps://github.com/rgstephens/node-red-contrib-graphqlhttps://www.cisa.gov/uscert/ics/advisories/icsa-22-258-05