CVE-2021-29060

Description

A Regular Expression Denial of Service (ReDOS) vulnerability was found in Color-String, which occurs when the application is provided and checks a crafted invalid HWB string. The highest threat from this vulnerability is to system availability.

Statement

OpenShift Service Mesh 1.1.x is in its maintenance phase, only Important and Critical vulnerabilities will be fixed at this time.

In OpenShift Container Platform (OCP) and OpenShift Service Mesh (OSSM) some components include the vulnerable color-string library, but access is protected by OpenShift OAuth what reducing impact by this flaw to LOW. Starting in OCP 4.7, the kibana component is shipping as "container first" content and as a part of the OpenShift Logging product (openshift-logging/kibana6-rhel8) and is not affected by this vulnerability. The kibana components delivered in OCP 4.6 and earlier are marked as Out of support scope because these versions are already under Maintenance Phase of the support.

In Red Hat Advanced Cluster Management for Kubernetes (RHACM) all containers are using the 1.5.5 fixed version, hence not RHACM version is affected by this flaw.

In Red Hat Virtualization a vulnerable version of color-string is used in ovirt-web-ui and ovirt-engine-ui-extensions. It is a build-time dependency not exploitable in the delivered product. Therefore impact is rated Low and it will not be immediately fixed. An update may be provided in future releases.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.35.3N/A
Attack VectorNetworkNetworkN/A
Attack ComplexityLowLowN/A
Privileges RequiredNoneNoneN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactLowLowN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Red Hat CVSS v3 Score Explanation

Successful attack may lead to a performance degradation, complete denial of service is not possible, therefore Availability metric is set to LOW.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

If an attacker can trigger the allocation of the limited resources, but the number or size of the resources is not controlled, then the most common result is denial of service. This would prevent valid users from accessing the product, and it could potentially have an impact on the surrounding environment, i.e., the product may slow down, crash due to unhandled errors, or lock out legitimate users. For example, a memory exhaustion attack against an application could slow down the application as well as its host operating system.

Access Control,Other

Technical Impact: Bypass Protection Mechanism; Other

In some cases it may be possible to force the product to "fail open" in the event of resource exhaustion. The state of the product -- and possibly the security functionality - may then be compromised.

Frequently Asked Questions

Want to get errata notifications? Sign up here.