Incorrect Regular Expression in marked - CVE-2022-21681

 

Incorrect Regular Expression in marked - CVE-2022-21681

Published: May 12, 2023


Vulnerability identifier: #VU76062
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-21681
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

marked
IBM Business Automation Manager Open Editions
Storage Defender – Data Protect
Cloud Pak for Multicloud Management Infrastructure Management
Storage Ceph
IBM Cloud Automation Manager
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
IBM Spectrum Protect Plus
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
golang-github-hashicorp-consul-sdk
gitqlient
golang-github-hashicorp-consul-api
Red Hat Ceph Storage
IBM Cognos Analytics

How to mitigate CVE-2022-21681

Install updates from vendor's website.

marked - update to 4.0.10
IBM Business Automation Manager Open Editions - update to 8.0.7
golang-github-hashicorp-consul-sdk - addressed in versions 0.13.0-1.fc36, 0.13.0-1.fc37
Storage Defender – Data Protect - update to 1.4.1
gitqlient - addressed in versions 1.5.0-2.el8, 1.5.0-2.fc36
golang-github-hashicorp-consul-api - addressed in versions 1.18.0-1.fc36, 1.18.0-1.fc37
Cloud Pak for Multicloud Management Infrastructure Management - update to 2.3 Fix Pack 5
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.4
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.6, 8.5
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1

External References

Related Security Bulletins