
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2021-3795 affects the semver-regex package and is related to inefficient regular expression complexity. The issue was discovered and disclosed in September 2021 (CVE Mitre, NVD).
The vulnerability is characterized by an inefficient regular expression pattern in the semver-regex package that could lead to Regular Expression Denial of Service (ReDoS). The fix involved modifying the regular expression pattern to include proper bounds and limits to prevent catastrophic backtracking (GitHub Commit).
The vulnerability could potentially lead to denial of service conditions when processing maliciously crafted input strings, affecting applications that use the semver-regex package for version string validation (Red Hat Advisory).
The vulnerability was fixed in an updated version of the semver-regex package. Users should update to the patched version to mitigate the risk. Red Hat has also released security updates for affected products including Red Hat Advanced Cluster Management (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."