Incorrect Regular Expression in is-svg - CVE-2021-28092
Published: May 10, 2021
Vulnerability identifier: #VU52986
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28092
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
is-svg
IBM Process Mining
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak System
IBM Process Mining
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak System
How to mitigate CVE-2021-28092
Install updates from vendor's website.
is-svg - update to 4.2.2
IBM Process Mining - update to 1.12.0.4
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.3
IBM Cloud Pak System - update to 2.3.3.5
IBM Process Mining - update to 1.12.0.4
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.3
IBM Cloud Pak System - update to 2.3.3.5