Incorrect regular expression in nth-check - CVE-2021-3803

 

Incorrect regular expression in nth-check - CVE-2021-3803

Published: May 16, 2023


Vulnerability identifier: #VU76185
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3803
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

nth-check
watsonx.data
watsonx Orchestrate Developer Edition
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
IBM Process Mining
Jira Service Management Data Center
Jira Software Data Center
QRadar User Behavior Analytics
Bitbucket Data Center
IBM Cloud Pak System
IBM Edge Application Manager
Splunk Enterprise
Ubuntu
node-nth-check (Ubuntu package)
Cloud Pak for Data
Bitbucket Server

How to mitigate CVE-2021-3803

Install updates from vendor's website.

nth-check - update to 2.0.1
watsonx Orchestrate Developer Edition - update to 1.15.0
IBM Process Mining - update to 1.12.0.4
watsonx.data - update to 2.3.1
IBM Cloud Pak System - update to 2.3.3.6
Jira Service Management Data Center - update to 10.3.22
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Jira Software Data Center - update to 10.3.22
node-nth-check (Ubuntu package) - addressed in versions 1.0.1-1+deb10u1build0.18.04.1, 1.0.1-1+deb10u1build0.20.04.1
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
QRadar User Behavior Analytics - update to 4.1.13
Cloud Pak for Data - update to 4.8.5
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25

External References

Related Security Bulletins