CVE-2021-27290 log

Source
Severity High
Remote Yes
Type Denial of service
Description
A security issue has been found in Node.js before versions 16.4.1, 14.17.2 and 12.22.2. There is a vulnerability in the ssri npm module which may be vulnerable to denial of service attacks.
Group Package Affected Fixed Severity Status Ticket
AVG-2129 nodejs-lts-dubnium 10.24.0-2 High Unknown
AVG-2128 nodejs-lts-erbium 12.22.0-2 12.22.3-1 High Fixed
AVG-2127 nodejs-lts-fermium 14.16.0-2 14.17.3-1 High Fixed
AVG-2126 nodejs 16.4.0-1 16.4.1-1 High Fixed
Date Advisory Group Package Severity Type
20 Jul 2021 ASA-202107-33 AVG-2128 nodejs-lts-erbium High multiple issues
20 Jul 2021 ASA-202107-32 AVG-2127 nodejs-lts-fermium High multiple issues
06 Jul 2021 ASA-202107-13 AVG-2126 nodejs High multiple issues
References
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/#npm-upgrade-ssri-regular-expression-denial-of-service-redos-high-cve-2021-27290
https://github.com/advisories/GHSA-vx3p-948g-6vhq
https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf
https://github.com/npm/ssri/pull/17
https://github.com/npm/ssri/commit/76e223317d971f19e4db8191865bdad5edee40d2