Incorrect Regular Expression in Lodash - CVE-2020-28500

 

Incorrect Regular Expression in Lodash - CVE-2020-28500

Published: June 27, 2021 / Updated: September 29, 2021


Vulnerability identifier: #VU54394
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-28500
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

Lodash
IBM VM Recovery Manager DR
IBM VM Recovery Manager HA GUI
Rational Performance Tester
DevOps Test Performance
Business Automation Insights
QRadar Assistant
MobileFirst Platform
cockpit-ovirt (Red Hat package)
ovirt-hosted-engine-ha (Red Hat package)
node-lodash (Ubuntu package)
ovirt-hosted-engine-setup (Red Hat package)
ovirt-host (Red Hat package)
vdsm (Red Hat package)
UCV – UrbanCode Velocity
IBM Cloud Transformation Advisor
IBM Security Guardium Insights
IBM Cloud Automation Manager
IBM Intelligent Operations Center
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Pak for Business Automation
IBM Process Mining
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Assistant for IBM Cloud Pak for Data
Use Case Manager App
Engineering Workflow Management
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Migration Toolkit for Containers
IBM Edge Application Manager
Red Hat OpenShift Jaeger
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat Virtualization Host
WordPress
IBM InfoSphere Information Server
Ubuntu
SINEC INS
Cloud Pak for Security (CP4S)
IBM Cloud Pak System
IBM Security QRadar Analyst Workflow
Engineering Lifecycle Management

How to mitigate CVE-2020-28500

Install update from vendor's website.

Lodash - update to 4.17.21
cockpit-ovirt (Red Hat package) - update to 0.15.1-2.el8ev
UCV – UrbanCode Velocity - update to 2.4.0
Migration Toolkit for Containers - update to 1.7.4
Red Hat OpenShift Jaeger - update to 1.20.4
ovirt-hosted-engine-ha (Red Hat package) - update to 2.4.8-1.el8ev
IBM Security Guardium Insights - update to 3.0
IBM Intelligent Operations Center - update to 5.2.4
WordPress - addressed in versions 5.2.12, 5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
DevOps Test Performance - update to 11.0.8
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
SINEC INS - update to 1.0 SP2
Cloud Pak for Security (CP4S) - update to 1.10.14.0
IBM Process Mining - update to 1.12.0.4
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.2
IBM Cloud Pak System - update to 2.3.3.5
node-lodash (Ubuntu package) - addressed in versions 2.4.1+dfsg-3ubuntu0.1~esm1, 4.17.4+dfsg-1ubuntu0.1~esm1, 4.17.15+dfsg-2ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1, 4.17.23+dfsg-1ubuntu0.1~esm1
ovirt-hosted-engine-setup (Red Hat package) - update to 2.5.3-1.el8ev
IBM Security QRadar Analyst Workflow - update to 2.15.1
QRadar Assistant - update to 3.6.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
Use Case Manager App - update to 4.0.0
ovirt-host (Red Hat package) - update to 4.4.8-2.el8ev
vdsm (Red Hat package) - update to 4.40.80.5-1.el8ev
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins