Resource exhaustion in UAParser.js - CVE-2021-27292
Published: August 9, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing a malicious User-Agent header. A remote attacker can trigger resource exhaustion and perform a regular expression denial of service (ReDoS) attack.
Affected software
OpenShift Logging
Red Hat OpenShift Jaeger
IBM Security QRadar Analyst Workflow
How to mitigate CVE-2021-27292
OpenShift Logging - addressed in versions 5.1.7, 5.2.6, 5.3.3
Red Hat OpenShift Jaeger - update to 1.24.0
IBM Security QRadar Analyst Workflow - update to 2.15.1
External References
Related Security Bulletins
- ReDoS vulnerability in UAParser.js library
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in OpenShift Logging
- Multiple vulnerabilities in Red Hat OpenShift Enterprise Logging
- Multiple vulnerabilities in Red Hat OpenShift Enterprise Logging
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow