VDB
RHSA-2023:7820
RHSA-2023:7820
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was found in the validator package. Affected versions of this package are vulnerable to Regular expression denial of service (ReDoS) attacks, affecting system availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | odf4/ocs-must-gather-rhel8@sha256:236b118b12fbd84139b4a4bd1b11577fb3b4defdda8f81410aa9d3d94d091dbb_s390x as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/odf-csi-addons-sidecar-rhel8@sha256:949e9256a096c2ce8a9423b0e5b43b437edf2afcea4562ce1fd70ad89dbfb3aa_s390x as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/odr-rhel8-operator@sha256:31c71fd8876661f6d2cb124aa9b090c445701b6f1ecb63d07dc0cdd462338c72_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/odr-rhel8-operator@sha256:31c71fd8876661f6d2cb124aa9b090c445701b6f1ecb63d07dc0cdd462338c72_ppc64le |
| Red Hat | odf4/ocs-operator-bundle@sha256:bcb41572adbe0bef128b29ed9541a2f46730b80e8cb178d47b1c3ee0dbf89b46_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-operator-bundle@sha256:bcb41572adbe0bef128b29ed9541a2f46730b80e8cb178d47b1c3ee0dbf89b46_ppc64le |
| Red Hat | odf4/odf-csi-addons-rhel8-operator@sha256:00ee14dc29e19896966cc83c2b9ecf8ef0adace88784e836e14941c4c715c2af_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/odf-csi-addons-rhel8-operator@sha256:00ee14dc29e19896966cc83c2b9ecf8ef0adace88784e836e14941c4c715c2af_s390x |
| Red Hat | odf4/mcg-core-rhel8@sha256:5badaef19e5c3db4aae1a050212fe7e11e2ffdd9b232da5427b03fa075a1bcb8_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/mcg-core-rhel8@sha256:5badaef19e5c3db4aae1a050212fe7e11e2ffdd9b232da5427b03fa075a1bcb8_ppc64le |
| Red Hat | odf4/odf-multicluster-operator-bundle@sha256:ec8527c4194453ae3fa7fedf9f11eb8e70f46f272736ac8c32e98b822a0a049f_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/odf-multicluster-operator-bundle@sha256:ec8527c4194453ae3fa7fedf9f11eb8e70f46f272736ac8c32e98b822a0a049f_amd64 |
| Red Hat | odf4/odf-csi-addons-operator-bundle@sha256:ab492146266cce67917cbed2f5bc1266c895f4f863790a487d5a4295b0805896_s390x as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/odr-hub-operator-bundle@sha256:fa2b5dd7db7bc0244660d7b4f95a2c06a6fd12a35f1e66449b85ac628cf960b2_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/odr-hub-operator-bundle@sha256:fa2b5dd7db7bc0244660d7b4f95a2c06a6fd12a35f1e66449b85ac628cf960b2_amd64 |
| Red Hat | odf4/odf-multicluster-rhel8-operator@sha256:27120e653977f168ae971f251c56d7d81243d6af69ab4ef18dce6c5546dd9641_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/odf-multicluster-rhel8-operator@sha256:27120e653977f168ae971f251c56d7d81243d6af69ab4ef18dce6c5546dd9641_s390x |
| Red Hat | odf4/odr-rhel8-operator@sha256:d9497c673469dc9dbc9b4a44fc7fa8fcdb7e795309d721660f5baa302f2b6ba9_s390x as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/mcg-core-rhel8@sha256:392340e4fd5a34c5e7daec8cb03bfd8ee256cc44a5358fab9aa598a5e6b23efb_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/mcg-core-rhel8@sha256:392340e4fd5a34c5e7daec8cb03bfd8ee256cc44a5358fab9aa598a5e6b23efb_s390x |
| Red Hat | odf4/ocs-operator-bundle@sha256:747dfd6f76eacea2f2d947e4d8130ce0b0122f9cd932f4c64854d0ce164eef27_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-operator-bundle@sha256:747dfd6f76eacea2f2d947e4d8130ce0b0122f9cd932f4c64854d0ce164eef27_s390x |
| Red Hat | odf4/mcg-rhel8-operator@sha256:606eaed06a442f11481538e980bf3a78db7f788f8008c410e49de6f8dcf2feb3_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/mcg-rhel8-operator@sha256:606eaed06a442f11481538e980bf3a78db7f788f8008c410e49de6f8dcf2feb3_s390x |
| Red Hat | odf4/mcg-operator-bundle@sha256:b21ba1915554201c5ef43abb66eac13482593fe31ce05a72cf909e4f385f5daf_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/mcg-operator-bundle@sha256:b21ba1915554201c5ef43abb66eac13482593fe31ce05a72cf909e4f385f5daf_ppc64le |
| Red Hat | odf4/odf-csi-addons-rhel8-operator@sha256:50957f5abc4e913bce3a59cb41f9ac8186d876b11a7417c65eeeea829953a66e_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/odf-csi-addons-rhel8-operator@sha256:50957f5abc4e913bce3a59cb41f9ac8186d876b11a7417c65eeeea829953a66e_ppc64le |
| Red Hat | odf4/odf-csi-addons-operator-bundle@sha256:0f33b6e8f7022b09dfeb92926783d39f3635325d4a36f82ae534cfae8c7b0a3b_ppc64le as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/cephcsi-rhel8@sha256:59fa82c420af8e3f8dd1695b121eb64c59f76f803770c59fd5c9025a64032663_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/cephcsi-rhel8@sha256:59fa82c420af8e3f8dd1695b121eb64c59f76f803770c59fd5c9025a64032663_ppc64le |
| Red Hat | odf4/odf-operator-bundle@sha256:d65ee2f23a5589b84b1959bf22660654a28a702eb095241f268fd3fa77224ae6_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/odf-operator-bundle@sha256:d65ee2f23a5589b84b1959bf22660654a28a702eb095241f268fd3fa77224ae6_s390x |
| Red Hat | odf4/odf-multicluster-rhel8-operator@sha256:96efdffd9c3f43d1cbed3468b6d4882e1e7a78f1aaca495c0e28e8cbbf71e540_ppc64le as a component of RHODF 4.12 for RHEL 8 | * |
…and 49 more
Timeline
- Dec 14, 2023 CVE Published
- Mar 21, 2026 CVE Updated
- May 2, 2026 Distribution Patch
- May 2, 2026 Distribution Patch
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:7820 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2126299 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2244765 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2246334 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2247112 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7820.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3765 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3765 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3765 advisory
- https://huntr.dev/bounties/c37e975c-21a3-4c5f-9b57-04d63b28cfc9 advisory