VDB

RHSA-2021%3A3694

RHSA-2021%3A3694 PUBLISHED CVSS 7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability was found in the nodejs axios. This flaw allows an attacker to provide crafted input to the trim function, which might cause high resources consumption and as a consequence lead to denial of service. The highest threat from this vulnerability is system availability.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhmtc/openshift-migration-velero-plugin-for-gcp-rhel8@sha256:b4272ea9b671da7ad0b1d9111e04b1a8505e7d9efe515d41495a8d3e56b4fb45_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8@sha256:b4272ea9b671da7ad0b1d9111e04b1a8505e7d9efe515d41495a8d3e56b4fb45_amd64
Red Hatrhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8@sha256:881751792fff5803a45a3f4d328d6fd4aaff4f188ea937d0a2b58597d6ee585d_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8@sha256:881751792fff5803a45a3f4d328d6fd4aaff4f188ea937d0a2b58597d6ee585d_amd64
Red Hatrhmtc/openshift-migration-log-reader-rhel8@sha256:efca0066bcee905c93b907d30f5a5dac779b5fdab573eba2a6af738c275658ff_amd64 as a component of 8Base-RHMTC-1.6*
Red Hatrhmtc/openshift-migration-rhel8-operator@sha256:5b1911b8e44a717866d7249abd966e487c6925e5eb77eaf507922866928badb6_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-rhel8-operator@sha256:5b1911b8e44a717866d7249abd966e487c6925e5eb77eaf507922866928badb6_amd64
Red Hatrhmtc/openshift-velero-plugin-rhel8@sha256:6d63774d8b54a62058ee03daf4056dde060f1415eee6b8323d5ebfcec4dd5f6e_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-velero-plugin-rhel8@sha256:6d63774d8b54a62058ee03daf4056dde060f1415eee6b8323d5ebfcec4dd5f6e_amd64
Red Hatrhmtc/openshift-migration-controller-rhel8@sha256:5dacb0bb125600adb6fecdc9ac583f38877960ae207cb21e925a1df4d36c9973_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-controller-rhel8@sha256:5dacb0bb125600adb6fecdc9ac583f38877960ae207cb21e925a1df4d36c9973_amd64
Red Hatrhmtc/openshift-migration-registry-rhel8@sha256:4603fc328b26a8dc454e1cb690f9d1b6534d2e51a806fc474158447fbe8fe6eb_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-registry-rhel8@sha256:4603fc328b26a8dc454e1cb690f9d1b6534d2e51a806fc474158447fbe8fe6eb_amd64
Red Hatrhmtc/openshift-migration-velero-plugin-for-aws-rhel8@sha256:02907e535f56c3c46921fe8a405adde11af6a43013ab467628f36a2bde708415_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-velero-plugin-for-aws-rhel8@sha256:02907e535f56c3c46921fe8a405adde11af6a43013ab467628f36a2bde708415_amd64
Red Hatrhmtc/openshift-migration-operator-bundle@sha256:f3dfe6ccf078244debab1ae4571b20b7ecd884cd8d382a6dc10f4a479dce2c34_amd64 as a component of 8Base-RHMTC-1.6*
Red Hatrhmtc/openshift-migration-must-gather-rhel8@sha256:4ecda5f0f4ab61eb28d2b513cf373a18d7965acf2c3f81845fa6b9ace90cc1d0_amd64 as a component of 8Base-RHMTC-1.6*
Red Hatrhmtc/openshift-migration-rsync-transfer-rhel8@sha256:3678c6f67225f0f37c022bc2604a6a5d78f15b7b57ba9073d06fa3466a3a0526_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:3678c6f67225f0f37c022bc2604a6a5d78f15b7b57ba9073d06fa3466a3a0526_amd64
Red Hatrhmtc/openshift-migration-ui-rhel8@sha256:19b8e2f0872faa1d1643d28aa3b893debfe22b102d049c02f335a622c29e3506_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-ui-rhel8@sha256:19b8e2f0872faa1d1643d28aa3b893debfe22b102d049c02f335a622c29e3506_amd64
Red Hatrhmtc/openshift-migration-velero-rhel8@sha256:697b57a7150f26cbc08ada7c8c5683819d87351cf713614ac9002706463c4392_amd64 as a component of 8Base-RHMTC-1.6*
Red Hatrhmtc/openshift-migration-velero-restic-restore-helper-rhel8@sha256:8ac2f63fe953daa4caba44e60c65ffa9d3c6653af72ce46cbe423b6da796f33c_amd64 as a component of 8Base-RHMTC-1.6rhmtc/openshift-migration-velero-restic-restore-helper-rhel8@sha256:8ac2f63fe953daa4caba44e60c65ffa9d3c6653af72ce46cbe423b6da796f33c_amd64

Timeline

  • Sep 29, 2021 CVE Published
  • Mar 18, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›