Incorrect Regular Expression in marked - CVE-2022-21680
Published: May 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to regular expression `block.def` may cause catastrophic backtracking against some strings. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
Storage Defender – Data Protect
Storage Ceph
IBM Cloud Automation Manager
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
IBM Spectrum Protect Plus
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
golang-github-hashicorp-consul-sdk
gitqlient
golang-github-hashicorp-consul-api
Red Hat Ceph Storage
IBM Cognos Analytics
How to mitigate CVE-2022-21680
golang-github-hashicorp-consul-sdk - addressed in versions 0.13.0-1.fc36, 0.13.0-1.fc37
Storage Defender – Data Protect - update to 1.4.1
gitqlient - addressed in versions 1.5.0-2.el8, 1.5.0-2.fc36
golang-github-hashicorp-consul-api - addressed in versions 1.18.0-1.fc36, 1.18.0-1.fc37
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.4
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.6, 8.5
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1
External References
- https://github.com/markedjs/marked/security/advisories/GHSA-rrrm-qjm4-v8hf
- https://github.com/markedjs/marked/commit/c4a3ccd344b6929afa8a1d50ac54a721e57012c0
- https://github.com/markedjs/marked/releases/tag/v4.0.10
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AIXDMC3CSHYW3YWVSQOXAWLUYQHAO5UX/
Related Security Bulletins
- Multiple vulnerabilities in IBM Cognos Analytics
- Incorrect Regular Expression in IBM Cloud Automation Manager
- Multiple vulnerabilities in Red Hat Ceph Storage
- Multiple vulnerabilities in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM Maximo Manage application in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Storage Ceph
- Fedora 36 update for gitqlient
- Fedora EPEL 8 update for gitqlient
- Fedora 36 update for golang-github-hashicorp-consul-sdk
- Fedora 37 update for golang-github-hashicorp-consul-sdk
- Fedora 37 update for golang-github-hashicorp-consul-api
- Fedora 36 update for golang-github-hashicorp-consul-api
- Multiple vulnerabilities in IBM Spectrum Protect Plus