Resource exhaustion in node-redis - CVE-2021-29469
Published: September 29, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources, when a client is in monitoring mode. A remote attacker can trigger resource exhaustion and perform a regular expression denial of service (ReDoS) attack.
Affected software
Cloud Pak for Security (CP4S)
IBM Cloud Automation Manager
IBM Cloud Application Performance Management (APM)
IBM Cognos Analytics
How to mitigate CVE-2021-29469
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.4