Schema-Inspector におけるリソースの枯渇に関する脆弱性
| Title |
Schema-Inspector におけるリソースの枯渇に関する脆弱性
|
| Summary |
Schema-Inspector には、リソースの枯渇に関する脆弱性、および入力確認に関する脆弱性が存在します。
|
| Possible impacts |
サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
March 14, 2021, midnight |
| Registration Date |
Dec. 2, 2021, 6:08 p.m. |
| Last Update |
Dec. 2, 2021, 6:08 p.m. |
|
CVSS3.0 : 重要
|
| Score |
7.5
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
|
CVSS2.0 : 警告
|
| Score |
5
|
| Vector |
AV:N/AC:L/Au:N/C:N/I:N/A:P |
Affected System
| Schema-Inspector project |
|
Schema-Inspector 2.0.0 未満
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2021年12月02日] 掲載 |
Dec. 2, 2021, 6:08 p.m. |
NVD Vulnerability Information
CVE-2021-21267
| Summary |
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `a@0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.`) will freeze the program or web browser page executing the code. This affects any current schema-inspector users using any version to validate email addresses. Users who do not do email validation, and instead do other types of validation (like string min or max length, etc), are not affected. Users should upgrade to version 2.0.0, which uses a regex expression that isn't vulnerable to ReDoS.
|
| Publication Date |
March 20, 2021, 6:15 a.m. |
| Registration Date |
March 20, 2021, 10:02 a.m. |
| Last Update |
Nov. 21, 2024, 2:47 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:schema-inspector_project:schema-inspector:*:*:*:*:*:node.js:*:* |
|
|
|
2.0.0 |
| Configuration2 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List