Resource exhaustion in axios - CVE-2021-3749

 

Resource exhaustion in axios - CVE-2021-3749

Published: September 30, 2021


Vulnerability identifier: #VU56963
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3749
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the isURLSearchParams function in utils.js. A remote attacker can send specially crafted data to the application and perform regular expression denial of service (ReDoS) attack.


Affected software

axios
Migration Toolkit for Containers
IBM Watson Discovery for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
SINEC INS
IBM i Modernization Engine for Lifecycle Integration
IBM Cloud Pak System
Oracle GoldenGate

How to mitigate CVE-2021-3749

Install updates from vendor's website.

axios - update to 0.21.2
Migration Toolkit for Containers - update to 1.6.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-5, 4.0.3
SINEC INS - update to 1.0 SP2
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Oracle GoldenGate - update to 21.7.0.0.0

External References

Related Security Bulletins