Incorrect Regular Expression in color-string - CVE-2021-29060
Published: May 26, 2022 / Updated: May 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when the application is provided and checks a crafted invalid HWB string. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
IBM Cloud Pak System
IBM Edge Application Manager
Splunk Enterprise
IBM Security QRadar Analyst Workflow
IBM Process Mining
QRadar User Behavior Analytics
How to mitigate CVE-2021-29060
IBM Cloud Pak System - update to 2.3.3.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Process Mining - update to 1.12.0.4
IBM Security QRadar Analyst Workflow - update to 2.15.1
QRadar User Behavior Analytics - update to 4.1.11
External References
Related Security Bulletins
- Incorrect Regular Expression in Qix color-string
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow
- Incorrect regular expression in IBM Cloud Pak System
- Incorrect regular expression in IBM Process Mining
- IBM Edge Application Manager update for color-string
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics