Incorrect Regular Expression in normalize-url - CVE-2021-33502
Published: May 26, 2022 / Updated: May 26, 2022
Vulnerability identifier: #VU63698
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33502
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to exponential performance for data. A remote attacker can pass specially crafted data to the application and perform a regular expression denial of service (ReDos) attack.
Affected software
normalize-url
QRadar Pulse App
IBM Cloud Transformation Advisor
IBM Security Guardium Insights
IBM Process Mining
IBM Sterling External Authentication Server
IBM Watson Machine Learning Accelerator
IBM Edge Application Manager
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Linux
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rh-nodejs12-nodejs-nodemon (Red Hat package)
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-nodemon
nodejs-nodemon (Red Hat package)
npm
rh-nodejs12-nodejs (Red Hat package)
rh-nodejs14-nodejs (Red Hat package)
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs (Red Hat package)
nodejs-packaging
IBM Cloud Pak System
IBM Security QRadar Analyst Workflow
IBM QRadar Data Synchronization App
QRadar Pulse App
IBM Cloud Transformation Advisor
IBM Security Guardium Insights
IBM Process Mining
IBM Sterling External Authentication Server
IBM Watson Machine Learning Accelerator
IBM Edge Application Manager
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Linux
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rh-nodejs12-nodejs-nodemon (Red Hat package)
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-nodemon
nodejs-nodemon (Red Hat package)
npm
rh-nodejs12-nodejs (Red Hat package)
rh-nodejs14-nodejs (Red Hat package)
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs (Red Hat package)
nodejs-packaging
IBM Cloud Pak System
IBM Security QRadar Analyst Workflow
IBM QRadar Data Synchronization App
How to mitigate CVE-2021-33502
Cybersecurity Help is currently unaware of any official solution to address this vulnerability..
normalize-url - addressed in versions 4.5.1, 5.3.1, 6.0.1
QRadar Pulse App - update to 2.2.9
IBM Security Guardium Insights - update to 3.0.1
IBM Process Mining - update to 1.12.0.4
rh-nodejs12-nodejs-nodemon (Red Hat package) - update to 2.0.3-2.el7
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.3-2.el7
nodejs-nodemon - update to 2.0.15-1
nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el9_0
IBM Cloud Pak System - update to 2.3.3.5
IBM Security QRadar Analyst Workflow - update to 2.15.1
IBM QRadar Data Synchronization App - update to 3.0.1
IBM Sterling External Authentication Server - update to 6.1.0.0 iFix02
npm - addressed in versions 6.14.15-1.14.18.2.2, 8.1.2-1.16.13.1.3
rh-nodejs12-nodejs (Red Hat package) - update to 12.22.2-1.el7
rh-nodejs14-nodejs (Red Hat package) - update to 14.17.2-1.el7
nodejs-docs - addressed in versions 14.18.2-2, 16.13.1-3
nodejs-full-i18n - addressed in versions 14.18.2-2, 16.13.1-3
nodejs-devel - addressed in versions 14.18.2-2, 16.13.1-3
nodejs - addressed in versions 14.18.2-2, 16.13.1-3
nodejs (Red Hat package) - update to 16.16.0-1.el9_0
nodejs-packaging - addressed in versions 23-3, 25-1
QRadar Pulse App - update to 2.2.9
IBM Security Guardium Insights - update to 3.0.1
IBM Process Mining - update to 1.12.0.4
rh-nodejs12-nodejs-nodemon (Red Hat package) - update to 2.0.3-2.el7
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.3-2.el7
nodejs-nodemon - update to 2.0.15-1
nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el9_0
IBM Cloud Pak System - update to 2.3.3.5
IBM Security QRadar Analyst Workflow - update to 2.15.1
IBM QRadar Data Synchronization App - update to 3.0.1
IBM Sterling External Authentication Server - update to 6.1.0.0 iFix02
npm - addressed in versions 6.14.15-1.14.18.2.2, 8.1.2-1.16.13.1.3
rh-nodejs12-nodejs (Red Hat package) - update to 12.22.2-1.el7
rh-nodejs14-nodejs (Red Hat package) - update to 14.17.2-1.el7
nodejs-docs - addressed in versions 14.18.2-2, 16.13.1-3
nodejs-full-i18n - addressed in versions 14.18.2-2, 16.13.1-3
nodejs-devel - addressed in versions 14.18.2-2, 16.13.1-3
nodejs - addressed in versions 14.18.2-2, 16.13.1-3
nodejs (Red Hat package) - update to 16.16.0-1.el9_0
nodejs-packaging - addressed in versions 23-3, 25-1
External References
Related Security Bulletins
- Incorrect Regular Expression in normalize-url
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Red Hat Enterprise Linux 9 update for nodejs and nodejs-nodemon
- Multiple vulnerabilities in IBM Security Guardium Insights
- Multiple vulnerabilities in IBM QRadar Pulse for QRadar SIEM
- Multiple vulnerabilities in Oracle Linux
- Red Hat Software Collections update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon
- Red Hat Software Collections update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon
- Incorrect regular expression in IBM Process Mining
- Incorrect Regular Expression in IBM Edge Application Manager
- Incorrect Regular Expression in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for the nodejs:16 module
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Multiple vulnerabilities in IBM Cloud Pak System
- Anolis OS update for nodejs:16 module
- Anolis OS update for nodejs:14 module