Inefficient regular expression complexity in fast-xml-parser - CVE-2024-41818

 

Inefficient regular expression complexity in fast-xml-parser - CVE-2024-41818

Published: September 18, 2024


Vulnerability identifier: #VU97478
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41818
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

fast-xml-parser
Software Support App (iOS)
Software Support app (Android)
console
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Security
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite
IBM Observability with Instana
QRadar Suite
Planning Analytics Local
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM App Connect Enterprise

How to mitigate CVE-2024-41818

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

fast-xml-parser - update to 4.4.1
Software Support App (iOS) - update to 2.0.0
Software Support app (Android) - update to 2.0.0
console - update to 1.7.2
QRadar Suite - update to 1.10.26.0
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
IBM Decision Optimization for Cloud Pak for Data - addressed in versions 4.8.6, 5.0.3
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.11, 4.16.2, 4.17.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3
IBM App Connect Enterprise - update to 12.0.12.5
IBM Observability with Instana - update to 284

External References

Related Security Bulletins