Incorrect Regular Expression in marked - CVE-2022-21680

 

Incorrect Regular Expression in marked - CVE-2022-21680

Published: May 12, 2023


Vulnerability identifier: #VU76061
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21680
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to regular expression `block.def` may cause catastrophic backtracking against some strings. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

marked
Storage Defender – Data Protect
Storage Ceph
IBM Cloud Automation Manager
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
IBM Spectrum Protect Plus
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
golang-github-hashicorp-consul-sdk
gitqlient
golang-github-hashicorp-consul-api
Red Hat Ceph Storage
IBM Cognos Analytics

How to mitigate CVE-2022-21680

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

marked - update to 4.0.10
golang-github-hashicorp-consul-sdk - addressed in versions 0.13.0-1.fc36, 0.13.0-1.fc37
Storage Defender – Data Protect - update to 1.4.1
gitqlient - addressed in versions 1.5.0-2.el8, 1.5.0-2.fc36
golang-github-hashicorp-consul-api - addressed in versions 1.18.0-1.fc36, 1.18.0-1.fc37
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.4
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.6, 8.5
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1

External References

Related Security Bulletins