VDB
RHSA-2023%3A5447
RHSA-2023%3A5447
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the Node.js word-wrap module, where it is vulnerable to a denial of service caused by a Regular expression denial of service (ReDoS) issue in the result variable. By sending a specially crafted regex input, a remote attacker can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhmtc/openshift-migration-log-reader-rhel8@sha256:4545c394465e23cd99f9204a8008074125bf0e54cf14191398fa36297622178c_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-log-reader-rhel8@sha256:4545c394465e23cd99f9204a8008074125bf0e54cf14191398fa36297622178c_amd64 |
| Red Hat | rhmtc/openshift-migration-hook-runner-rhel8@sha256:4ec5b490b6347b9816102e477e8c65d7fa692d4d8d81830e22d359be136693fc_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-hook-runner-rhel8@sha256:4ec5b490b6347b9816102e477e8c65d7fa692d4d8d81830e22d359be136693fc_amd64 |
| Red Hat | rhmtc/openshift-migration-ui-rhel8@sha256:d038c397009aaab72c067c65e3d2f58e77e3d8d8875f3e4d7c01c4d980c88139_amd64 as a component of 8Base-RHMTC-1.8 | * |
| Red Hat | rhmtc/openshift-migration-rhel8-operator@sha256:f7a98e85dfeb7e25aac72654958b6daff79e3afbad3e05b4a9c8aab766970065_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-rhel8-operator@sha256:f7a98e85dfeb7e25aac72654958b6daff79e3afbad3e05b4a9c8aab766970065_amd64 |
| Red Hat | rhmtc/openshift-migration-registry-rhel8@sha256:47fc548f5992663a660168b61480b28e9747994ce2763a28c5d09318c1f76e97_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-registry-rhel8@sha256:47fc548f5992663a660168b61480b28e9747994ce2763a28c5d09318c1f76e97_amd64 |
| Red Hat | rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:9f9d3f87ded448205f4e3add44c2867c9df78b21b2f17cb1ecdce7000178d747_amd64 as a component of 8Base-RHMTC-1.8 | * |
| Red Hat | rhmtc/openshift-migration-controller-rhel8@sha256:a6ffbd8eceec6cbcf1cd9e2a68bf054d83bc503a23e0761f31fd72bc2e0069e5_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-controller-rhel8@sha256:a6ffbd8eceec6cbcf1cd9e2a68bf054d83bc503a23e0761f31fd72bc2e0069e5_amd64 |
| Red Hat | rhmtc/openshift-migration-openvpn-rhel8@sha256:817c27901dd3e98fd43d81193c5a060c31b346616a8634338b3f281e1a11f2f3_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-openvpn-rhel8@sha256:817c27901dd3e98fd43d81193c5a060c31b346616a8634338b3f281e1a11f2f3_amd64 |
| Red Hat | rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:9c5cfbf88d5a9ed70d7ae1b9685558307b5822c01ed9bdea87002070edadcec7_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:9c5cfbf88d5a9ed70d7ae1b9685558307b5822c01ed9bdea87002070edadcec7_amd64 |
| Red Hat | rhmtc/openshift-migration-operator-bundle@sha256:0e34493173d117c7018af4ef6c0ab2638442acd01b9aeab9cc3ac0888906148c_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-operator-bundle@sha256:0e34493173d117c7018af4ef6c0ab2638442acd01b9aeab9cc3ac0888906148c_amd64 |
| Red Hat | rhmtc/openshift-migration-must-gather-rhel8@sha256:575ca0d0f249d4cacea752057aa632da0e1b10d409d67ea07c5546ffbfff6ee7_amd64 as a component of 8Base-RHMTC-1.8 | rhmtc/openshift-migration-must-gather-rhel8@sha256:575ca0d0f249d4cacea752057aa632da0e1b10d409d67ea07c5546ffbfff6ee7_amd64 |
Timeline
- Oct 5, 2023 CVE Published
- Apr 30, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:5447 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2216827 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2233026 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2233097 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2233103 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2233868 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2238974 issue
- https://issues.redhat.com/browse/MIG-1331 advisory
- https://issues.redhat.com/browse/MIG-1363 advisory
- https://issues.redhat.com/browse/MIG-1411 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5447.json advisory
- https://access.redhat.com/security/cve/CVE-2023-26115 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-26115 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-26115 advisory