CVE-2021-27290

Name
CVE-2021-27290
Description
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf
Product https://npmjs.com
Exploit https://github.com/yetingli/SaveResults/blob/main/pdf/ssri-redos.pdf
MISC https://www.oracle.com/security-alerts/cpuoct2021.html
CONFIRM https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ssri_project:ssri:*:*:*:*:*:node.js:*:* ssri >= 5.2.2 < 6.0.2
cpe:2.3:a:ssri_project:ssri:*:*:*:*:*:node.js:*:* ssri >= 7.0.0 < 8.0.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status