Description

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

INFO

Published Date :

2024-11-08T05:00:04.695Z

Last Modified :

2025-05-20T14:38:35.942Z

Source :

snyk
AFFECTED PRODUCTS

The following products are affected by CVE-2024-21538 vulnerability.

Vendors Products
Cross-spawn
  • Cross-spawn
Redhat
  • Advanced Cluster Security
  • Discovery
  • Openshift
  • Openshift Ai
  • Openshift Data Foundation
  • Openshift Devspaces
  • Rhdh
  • Rhmt
  • Service Mesh
  • Trusted Artifact Signer
  • Trusted Profile Analyzer

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact