漏洞信息详情
ssri 安全漏洞
漏洞简介
nlf ssri是 (nlf)开源的一个应用软件。提供Standard Subresource Integrity(标准子资源完整性)的缩写,是一个Node.js实用程序,用于解析,操作,序列化,生成和验证Subresource Integrity哈希值。
ssri 5.2.2-8.0.0 存在安全漏洞,该漏洞源于使用正则表达式处理SRIs,该正则表达式容易被拒绝服务。恶意的SRIs可能需要非常长的时间来处理,从而导致拒绝服务。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf
参考网址
来源:MISC
链接:https://github.com/yetingli/SaveResults/blob/main/pdf/ssri-redos.pdf
来源:MISC
链接:https://npmjs.com
来源:MISC
链接:https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101939
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-27290
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-integration-bus-ibm-app-connect-enterprise-v11-are-affected-by-vulnerabilities-in-node-js-cve-2021-27290-2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2408
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2649
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2682
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2566
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2641
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164257/Red-Hat-Security-Advisory-2021-3638-01.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-integration-bus-ibm-app-connect-enterprise-v11-are-affected-by-vulnerabilities-in-node-js-cve-2021-27290/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Node-js-Core-three-vulnerabilities-35816
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3190
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021041364
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6497077
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163778/Red-Hat-Security-Advisory-2021-3074-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163694/Red-Hat-Security-Advisory-2021-2932-01.html
受影响实体
暂无
补丁
- ssri 安全漏洞的修复措施<!--2021-3-12-->
还没有评论,来说两句吧...