CVE-2021-27290

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ssri_project:ssri:*:*:*:*:*:node.js:*:*
cpe:2.3:a:ssri_project:ssri:*:*:*:*:*:node.js:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm:21.2.0:*:*:*:enterprise:*:*:*

Configuration 3 (hide)

cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*

Information

Published : 2021-03-12 14:15

Updated : 2022-05-13 13:51


NVD link : CVE-2021-27290

Mitre link : CVE-2021-27290


JSON object : View

Advertisement

dedicated server usa

Products Affected

ssri_project

  • ssri

oracle

  • graalvm

siemens

  • sinec_infrastructure_network_services