Inefficient regular expression complexity in AngularJS - CVE-2022-25844
Published: March 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to angular provides a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
IBM Tivoli Netcool Impact
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Tivoli Business Service Manager
IBM Sterling Control Center
IBM MQ
Fedora
HPE Unified OSS Console (UOC)
glances
IBM OpenPages with Watson
IBM MQ Appliance
AirWave Management Platform
How to mitigate CVE-2022-25844
HPE Unified OSS Console (UOC) - update to 3.1.8
glances - addressed in versions 3.3.0.1-1.el8, 3.3.0.1-1.el9, 3.3.0.1-2.fc35, 3.3.0.1-2.fc36
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.1
IBM Tivoli Business Service Manager - update to 6.2.0.4
IBM Sterling Control Center - addressed in versions 6.2.1.0.11, 6.3.0.0.2
IBM OpenPages with Watson - addressed in versions 8.3.0.2.7, 9.0.0.1
AirWave Management Platform - update to 8.3.0.4
IBM MQ Appliance - update to 9.3.0.0
IBM MQ - update to 9.3.0
External References
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2772737
- https://snyk.io/vuln/SNYK-JS-ANGULAR-2772735
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2772736
- https://stackblitz.com/edit/angularjs-material-blank-zvtdvb
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2772738
- https://security.netapp.com/advisory/ntap-20220629-0009/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WUSPYOTOMAZPDEFPWPSCSPMNODRDKK3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LNAKCNTVBIHWAUT3FKWV5N67PQXSZOO/
Related Security Bulletins
- Inefficient regular expression complexity in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM MQ Appliance
- Multiple vulnerabilities in IBM MQ
- Inefficient regular expression complexity in IBM Sterling Control Center
- Fedora 36 update for glances
- Fedora 35 update for glances
- Fedora EPEL 9 update for glances
- Fedora EPEL 8 update for glances
- Multiple vulnerabilities in HPE Aruba Networking AirWave Management Platform
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)