VDB
RHBA-2024%3A10760
RHBA-2024%3A10760
PUBLISHED
CVSS 4.400000095367432 MEDIUM
A Regular Expression Denial of Service (ReDoS) vulnerability was found in the cross-spawn package for Node.js. Due to improper input sanitization, an attacker can increase CPU usage and crash the program with a large, specially crafted string.
Risk Scores
CVSS 3.1
4.400000095367432
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhdh/rhdh-operator-bundle@sha256:1da349194fc014e578fe3d568142769dbbc86212ee030fbcc7fe769f1f16053a_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | rhdh/rhdh-operator-bundle@sha256:1da349194fc014e578fe3d568142769dbbc86212ee030fbcc7fe769f1f16053a_amd64 |
| Red Hat | rhdh/rhdh-rhel9-operator@sha256:7c8d747bd3a39eebe83a3b88f9136bc1a5c17114550c0db059b7cf74d3d2caf1_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | rhdh/rhdh-rhel9-operator@sha256:7c8d747bd3a39eebe83a3b88f9136bc1a5c17114550c0db059b7cf74d3d2caf1_amd64 |
| Red Hat | rhdh/rhdh-hub-rhel9@sha256:5173269a9ba82b51d892feb8eaba934340b5defe2f52a20bcacfcca7a81ae6e2_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | rhdh/rhdh-hub-rhel9@sha256:5173269a9ba82b51d892feb8eaba934340b5defe2f52a20bcacfcca7a81ae6e2_amd64 |
Timeline
- Dec 17, 2024 CVE Published
- Apr 30, 2026 CVE Updated
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHBA-2024:10760 advisory
- https://docs.redhat.com/en/documentation/red_hat_developer_hub/1.3 advisory
- https://issues.redhat.com/browse/RHIDP-4904 advisory
- https://issues.redhat.com/browse/RHIDP-4905 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_10760.json advisory
- https://access.redhat.com/security/cve/CVE-2024-21538 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2324550 issue
- https://www.cve.org/CVERecord?id=CVE-2024-21538 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-21538 advisory
- https://github.com/moxystudio/node-cross-spawn/commit/5ff3a07d9add449021d806e45c4168203aa833ff advisory
- https://github.com/moxystudio/node-cross-spawn/commit/640d391fde65388548601d95abedccc12943374f advisory
- https://github.com/moxystudio/node-cross-spawn/pull/160 advisory
- https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230 advisory