VDB
BDU%3A2024-09421
BDU%3A2024-09421
PUBLISHED
CVSS 5 MEDIUM
Уязвимость библиотеки micromatch, связанная с неэффективной сложностью регулярных выражений, позволяющая нарушителю получить вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Fedora Project | Red Hat Enterprise Linux, JBoss Enterprise Application Platform, Red Hat JBoss Data Grid, Red Hat Process Automation, Red Hat 3scale API Management Platform, Red Hat Integration Camel K, Debian GNU/Linux, Red Hat Data Grid, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat Satellite, Fedora, OpenShift Serverless, Red Hat Discovery, Cryostat, Red Hat build of OptaPlanner, Red Hat Developer Hub, Red Hat Fuse, micromatch, Openshift Service Mesh |
Timeline
- Nov 14, 2024 CVE Published
References
- https://advisory.checkmarx.net/advisory/CVE-2024-4067/ url
- https://devhub.checkmarx.com/cve-details/CVE-2024-4067/ url
- https://github.com/micromatch/micromatch/commit/03aa8052171e878897eee5d7bb2ae0ae83ec2ade url
- https://github.com/micromatch/micromatch/pull/266 url
- https://github.com/micromatch/micromatch/releases/tag/4.0.8 url
- https://redos.red-soft.ru/support/secure/ url
- https://linuxsecurity.com/advisories/fedora/fedora-39-yarnpkg-2024-d79685d847-security-advisory-updates-sr5zu722oijx url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://security-tracker.debian.org/tracker/CVE-2024-4067 advisory
- https://access.redhat.com/security/cve/CVE-2024-4067 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-78df19aaf3 advisory