Incorrect Regular Expression in minimatch - CVE-2022-3517

 

Incorrect Regular Expression in minimatch - CVE-2022-3517

Published: December 6, 2022


Vulnerability identifier: #VU69942
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3517
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

minimatch
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Fedora
Ubuntu
openEuler
Migration Toolkit for Runtimes
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Process Mining
App Connect Enterprise Certified Container
Confluence Data Center
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
IBM Cloud Pak for Business Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
IBM Spectrum Protect Plus
IBM Robotic Process Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Cloud Pak for Security (CP4S)
Jira Software Server
DB2 Data Management Console
Storage Fusion Data Foundation
Business Automation Insights
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM i Modernization Engine for Lifecycle Integration
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Dell Policy Manager for Secure Connect Gateway (SCG)
Storage Ceph
Robotic Process Automation for Cloud Pak
IBM Edge Application Manager
IBM Spectrum Protect Backup-Archive Client
Splunk Enterprise
IBM Security QRadar Analyst Workflow
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
yarnpkg
nodejs-nodemon
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-nodemon (Red Hat package)
nodejs-minimatch
node-minimatch (Ubuntu package)
npm
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-docs
rh-nodejs14-nodejs (Red Hat package)
nodejs (Red Hat package)
nodejs-packaging
IBM Cloud Pak System
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Spectrum Protect for Space Management

How to mitigate CVE-2022-3517

Install update from vendor's website.

minimatch - update to 3.0.5
Migration Toolkit for Runtimes - update to 1.0.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Process Mining - update to 1.13.2
DB2 Data Management Console - update to 3.1.13
App Connect Enterprise Certified Container - update to 7.1.0
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Jira Software Server - update to 10.3.14
Jira Software Data Center - update to 10.3.14
Jira Service Management Server - update to 10.3.14
Jira Service Management Data Center - update to 10.3.14
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 1.8.0
yarnpkg - addressed in versions 1.22.19-3.fc36, 1.22.19-3.fc37, 1.22.19-5.el9
nodejs-nodemon - addressed in versions 2.0.20-2, 2.0.20-3
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el7
nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el9_1
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.7.0
IBM Security QRadar Analyst Workflow - update to 2.32.0
nodejs-minimatch - update to 3.0.4-2
node-minimatch (Ubuntu package) - addressed in versions 3.0.4-3+deb10u1build0.18.04.1, 3.0.4-4ubuntu0.1
Red Hat OpenShift Dev Spaces - update to 3.24.0
QRadar User Behavior Analytics - update to 4.1.13
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Storage Ceph - update to 6.1
npm - addressed in versions 6.14.17-1.14.21.1.2.0.1, 6.14.18-1.14.21.3.1.0.1
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Spectrum Protect Plus - update to 10.1.14
nodejs - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-devel - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-full-i18n - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
nodejs-docs - addressed in versions 14.21.1-2.0.1, 14.21.3-1.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.1-3.el7
nodejs (Red Hat package) - update to 16.18.1-3.el9_1
IBM Robotic Process Automation - update to 21.0.7.1
Robotic Process Automation for Cloud Pak - update to 21.0.7.1
nodejs-packaging - update to 23-3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-4

External References

Related Security Bulletins