Incorrect Regular Expression in minimatch - CVE-2022-3517
Published: December 6, 2022
Vulnerability identifier: #VU69942
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3517
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
minimatch
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Fedora
Ubuntu
openEuler
Migration Toolkit for Runtimes
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Process Mining
App Connect Enterprise Certified Container
Confluence Data Center
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
IBM Cloud Pak for Business Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
IBM Spectrum Protect Plus
IBM Robotic Process Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Cloud Pak for Security (CP4S)
Jira Software Server
DB2 Data Management Console
Storage Fusion Data Foundation
Business Automation Insights
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM i Modernization Engine for Lifecycle Integration
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Dell Policy Manager for Secure Connect Gateway (SCG)
Storage Ceph
Robotic Process Automation for Cloud Pak
IBM Edge Application Manager
IBM Spectrum Protect Backup-Archive Client
Splunk Enterprise
IBM Security QRadar Analyst Workflow
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
yarnpkg
nodejs-nodemon
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-nodemon (Red Hat package)
nodejs-minimatch
node-minimatch (Ubuntu package)
npm
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-docs
rh-nodejs14-nodejs (Red Hat package)
nodejs (Red Hat package)
nodejs-packaging
IBM Cloud Pak System
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Spectrum Protect for Space Management
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Fedora
Ubuntu
openEuler
Migration Toolkit for Runtimes
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Process Mining
App Connect Enterprise Certified Container
Confluence Data Center
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
IBM Cloud Pak for Business Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
IBM Spectrum Protect Plus
IBM Robotic Process Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Cloud Pak for Security (CP4S)
Jira Software Server
DB2 Data Management Console
Storage Fusion Data Foundation
Business Automation Insights
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM i Modernization Engine for Lifecycle Integration
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Dell Policy Manager for Secure Connect Gateway (SCG)
Storage Ceph
Robotic Process Automation for Cloud Pak
IBM Edge Application Manager
IBM Spectrum Protect Backup-Archive Client
Splunk Enterprise
IBM Security QRadar Analyst Workflow
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
yarnpkg
nodejs-nodemon
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-nodemon (Red Hat package)
nodejs-minimatch
node-minimatch (Ubuntu package)
npm
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-docs
rh-nodejs14-nodejs (Red Hat package)
nodejs (Red Hat package)
nodejs-packaging
IBM Cloud Pak System
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Spectrum Protect for Space Management
How to mitigate CVE-2022-3517
Install update from vendor's website.
minimatch - update to 3.0.5
Migration Toolkit for Runtimes - update to 1.0.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Process Mining - update to 1.13.2
DB2 Data Management Console - update to 3.1.13
App Connect Enterprise Certified Container - update to 7.1.0
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Jira Software Server - update to 10.3.14
Jira Software Data Center - update to 10.3.14
Jira Service Management Server - update to 10.3.14
Jira Service Management Data Center - update to 10.3.14
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 1.8.0
yarnpkg - addressed in versions 1.22.19-3.fc36, 1.22.19-3.fc37, 1.22.19-5.el9
nodejs-nodemon - addressed in versions 2.0.20-2, 2.0.20-3
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el7
nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el9_1
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.7.0
IBM Security QRadar Analyst Workflow - update to 2.32.0
nodejs-minimatch - update to 3.0.4-2
node-minimatch (Ubuntu package) - addressed in versions 3.0.4-3+deb10u1build0.18.04.1, 3.0.4-4ubuntu0.1
Red Hat OpenShift Dev Spaces - update to 3.24.0
QRadar User Behavior Analytics - update to 4.1.13
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Storage Ceph - update to 6.1
npm - addressed in versions 6.14.17-1.14.21.1.2.0.1, 6.14.18-1.14.21.3.1.0.1
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Spectrum Protect Plus - update to 10.1.14
nodejs - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-devel - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-full-i18n - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-docs - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.1-3.el7
nodejs (Red Hat package) - update to 16.18.1-3.el9_1
IBM Robotic Process Automation - update to 21.0.7.1
Robotic Process Automation for Cloud Pak - update to 21.0.7.1
nodejs-packaging - update to 23-3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-4
Migration Toolkit for Runtimes - update to 1.0.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Process Mining - update to 1.13.2
DB2 Data Management Console - update to 3.1.13
App Connect Enterprise Certified Container - update to 7.1.0
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Jira Software Server - update to 10.3.14
Jira Software Data Center - update to 10.3.14
Jira Service Management Server - update to 10.3.14
Jira Service Management Data Center - update to 10.3.14
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 1.8.0
yarnpkg - addressed in versions 1.22.19-3.fc36, 1.22.19-3.fc37, 1.22.19-5.el9
nodejs-nodemon - addressed in versions 2.0.20-2, 2.0.20-3
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el7
nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el9_1
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.7.0
IBM Security QRadar Analyst Workflow - update to 2.32.0
nodejs-minimatch - update to 3.0.4-2
node-minimatch (Ubuntu package) - addressed in versions 3.0.4-3+deb10u1build0.18.04.1, 3.0.4-4ubuntu0.1
Red Hat OpenShift Dev Spaces - update to 3.24.0
QRadar User Behavior Analytics - update to 4.1.13
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Storage Ceph - update to 6.1
npm - addressed in versions 6.14.17-1.14.21.1.2.0.1, 6.14.18-1.14.21.3.1.0.1
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Spectrum Protect Plus - update to 10.1.14
nodejs - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-devel - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-full-i18n - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-docs - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.1-3.el7
nodejs (Red Hat package) - update to 16.18.1-3.el9_1
IBM Robotic Process Automation - update to 21.0.7.1
Robotic Process Automation for Cloud Pak - update to 21.0.7.1
nodejs-packaging - update to 23-3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-4
External References
Related Security Bulletins
- Regular expression denial of service in minimatch
- Red Hat Enterprise Linux 8 update for the nodejs:18 module
- Red Hat Enterprise Linux 9 update for the nodejs:18 module
- Regular expression denial of service in IBM Watson Assistant for IBM Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for the nodejs:16 module
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 9 update for nodejs and nodejs-nodemon
- Incorrect regular expression in IBM Process Mining
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Incorrect regular expression in IBM Robotic Process Automation
- Red Hat Software Collections update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Incorrect regular expression in IBM Cloud Pak for Integration (CP4I)
- Denial of service in App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Spectrum Protect Plus File Systems Agent
- Multiple vulnerabilities in IBM Spectrum Protect Client and IBM Spectrum Protect for Space Management
- Red Hat Enterprise Linux 8.4 Extended Update Support update for the nodejs:14 module
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Red Hat Enterprise Linux 8.6 Extended Update Support update for the nodejs:14 module
- Multiple vulnerabilities in Oracle Linux
- Incorrect Regular Expression in IBM Edge Application Manager
- Ubuntu update for node-minimatch
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Data Virtualization on Cloud Pak for Data
- Fedora 37 update for yarnpkg
- Fedora 36 update for yarnpkg
- Fedora EPEL 9 update for yarnpkg
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Analyst Workflow
- openEuler update for nodejs-minimatch
- Multiple vulnerabilities in IBM i Modernization Engine for Lifecycle Integration
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Incorrect Regular Expression in Storage Ceph
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Confluence Data Center update for minimatch
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.6
- Anolis OS update for nodejs:14 module
- Anolis OS update for nodejs:14 module
- IBM Storage Fusion Data Foundation update for minimatch package
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Business Automation Insights
- Jira Software Data Center and Server update for minimatch
- Jira Service Management Data Center and Server update for minimatch
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM DB2 Data Management Console update for minimatch