Inefficient regular expression complexity in AngularJS - CVE-2022-25844

 

Inefficient regular expression complexity in AngularJS - CVE-2022-25844

Published: March 7, 2024


Vulnerability identifier: #VU87188
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25844
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to angular provides a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

AngularJS
IBM Tivoli Netcool Impact
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Tivoli Business Service Manager
IBM Sterling Control Center
IBM MQ
Fedora
HPE Unified OSS Console (UOC)
glances
IBM OpenPages with Watson
IBM MQ Appliance
AirWave Management Platform

How to mitigate CVE-2022-25844

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

IBM Tivoli Netcool Impact - update to 7.1.0.31
HPE Unified OSS Console (UOC) - update to 3.1.8
glances - addressed in versions 3.3.0.1-1.el8, 3.3.0.1-1.el9, 3.3.0.1-2.fc35, 3.3.0.1-2.fc36
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.1
IBM Tivoli Business Service Manager - update to 6.2.0.4
IBM Sterling Control Center - addressed in versions 6.2.1.0.11, 6.3.0.0.2
IBM OpenPages with Watson - addressed in versions 8.3.0.2.7, 9.0.0.1
AirWave Management Platform - update to 8.3.0.4
IBM MQ Appliance - update to 9.3.0.0
IBM MQ - update to 9.3.0

External References

Related Security Bulletins