Input validation error in serve - CVE-2021-3807

 

Input validation error in serve - CVE-2021-3807

Published: November 5, 2021 / Updated: July 15, 2022


Vulnerability identifier: #VU57967
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-3807
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
serve
amcharts
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise High Performance Computing 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy Module
SUSE Manager Server Module
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
SUSE Manager Client Tools Beta for SLE Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Linux
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Manager Client Tools for SLE
SUSE Manager Client Tools Beta for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Package Hub 15
openSUSE Leap
QRadar Pulse App
Grafana
rhv-log-collector-analyzer (Red Hat package)
ovirt-engine-ui-extensions (Red Hat package)
ovirt-web-ui (Red Hat package)
ovirt-engine-dwh (Red Hat package)
ovirt-engine (Red Hat package)
rhvm-branding-rhv (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
firewalld-prometheus-config
dracut-saltboot
kiwi-desc-saltboot
golang-github-QubitProducts-exporter_exporter
wire
wire-debuginfo
prometheus-postgres_exporter
golang-github-prometheus-promu
prometheus-blackbox_exporter-debuginfo
prometheus-blackbox_exporter
golang-github-prometheus-alertmanager
golang-github-lusitaniae-apache_exporter
system-user-prometheus
system-user-grafana
golang-github-lusitaniae-apache_exporter-debuginfo
python2-zypp-plugin-spacewalk
zypp-plugin-spacewalk
python3-zypp-plugin-spacewalk
supportutils-plugin-salt
golang-github-prometheus-node_exporter
golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter-debuginfo
apache-commons-compress (Red Hat package)
nodejs-common
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-nodemon
nodejs-nodemon (Red Hat package)
python2-hwdata
python3-hwdata
ansible-doc
ansible
golang-github-prometheus-prometheus
mgr-daemon
python2-uyuni-common-libs
python3-uyuni-common-libs
uyuni-proxy-systemd-services
spacewalk-client-setup
python2-spacewalk-check
spacewalk-client-tools
spacewalk-check
python2-spacewalk-client-tools
python2-spacewalk-client-setup
python3-spacewalk-check
python3-spacewalk-client-setup
python3-spacewalk-client-tools
spacecmd
ovirt-log-collector (Red Hat package)
ovirt-dependencies (Red Hat package)
python2-mgr-push
mgr-push
supportutils-plugin-susemanager-client
python2-rhnlib
python3-mgr-push
python3-rhnlib
python3-pyvmomi
npm
nodejs8-docs
nodejs8
nodejs8-debuginfo
nodejs8-debugsource
nodejs8-devel
npm8
grafana
grafana-debuginfo
libns1604-32bit
libisccc1600-debuginfo
libisccc1600
libbind9-1600
libisccfg1600
bind-utils
libdns1605
libirs1601
bind-devel-32bit
libisccc1600-32bit-debuginfo
libdns1605-32bit-debuginfo
libirs1601-32bit-debuginfo
libns1604-32bit-debuginfo
libdns1605-32bit
libisccfg1600-32bit
libbind9-1600-32bit
libisccc1600-32bit
libirs1601-32bit
libisc1606-32bit-debuginfo
libbind9-1600-32bit-debuginfo
libisc1606-32bit
libisccfg1600-32bit-debuginfo
python3-bind
bind-doc
libisccfg1600-debuginfo
libirs-devel
bind-chrootenv
bind-debugsource
libirs1601-debuginfo
libdns1605-debuginfo
libns1604-debuginfo
libbind9-1600-debuginfo
libisc1606-debuginfo
bind-devel
bind
bind-utils-debuginfo
bind-debuginfo
libns1604
libisc1606-64bit
libisccfg1600-64bit
libirs1601-64bit
libbind9-1600-64bit
libdns1605-64bit
libisccc1600-64bit
libisc1606
nodejs10-docs
npm10
nodejs10-devel
nodejs10-debugsource
nodejs10-debuginfo
nodejs10
nodejs12-devel
npm12
nodejs12-docs
nodejs12-debugsource
nodejs12-debuginfo
nodejs12
rh-nodejs14-nodejs (Red Hat package)
nodejs-docs
nodejs-full-i18n
nodejs
nodejs-devel
nodejs14
nodejs14-docs
nodejs14-debuginfo
npm14
nodejs14-devel
nodejs14-debugsource
nodejs (Red Hat package)
nodejs-packaging
postgresql-jdbc (Red Hat package)
Migration Toolkit for Containers
IBM Edge Application Manager
IBM Spectrum Protect Backup-Archive Client
Cloud Pak for Security (CP4S)
Jira Software Server
IBM QRadar Data Synchronization App
Oracle Communications Cloud Native Core Policy
IBM Spectrum Protect for Space Management
IBM Cloud Transformation Advisor
IBM Intelligent Operations Center
Bitbucket Data Center
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
IBM Cloud Pak for Business Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Netcool Operations Insight
QRadar User Behavior Analytics
IBM Spectrum Protect Plus
IBM Watson Machine Learning Accelerator
Storage Fusion Data Foundation
Business Automation Insights
Storage Defender – Data Protect
QRadar Deployment Intelligence App
EMC Cloud Tiering Appliance
Red Hat Virtualization Manager
Bitbucket Server
IBM Cloud Pak System
OpenShift Data Foundation (formerly OpenShift Container Storage)

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when matching crafted invalid ANSI escape codes in ansi-regex. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


How to mitigate CVE-2021-3807

Install updates from vendor's website.

Sources