CVE-2021-29469: Potential exponential regex in monitor mode
FasterXML jackson-databind is vulnerable to a denial of service, caused by an error when using JDK serialization to serialize and deserialize JsonNode values. By sending a specially crafted request, an attacker could exploit this vulnerability to cause a denial of service.
Other sources
Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service. The issue is patched in version 3.1.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-29469?
CVE-2021-29469 is a denial of service vulnerability in the Node Redis redis module for Node.js.
How does CVE-2021-29469 impact IBM Cognos Analytics 11.2.x?
CVE-2021-29469 can cause a denial of service condition in IBM Cognos Analytics 11.2.x.
Is CVE-2021-29469 a high severity vulnerability?
Yes, CVE-2021-29469 has a severity value of 7.5, indicating a high severity.
How can I fix CVE-2021-29469 in IBM Cognos Analytics 11.2.x?
You can fix CVE-2021-29469 in IBM Cognos Analytics 11.2.x by applying the patch available at [link to patch].
Where can I find more information about CVE-2021-29469?
You can find more information about CVE-2021-29469 at [link to IBM X-Force exchange] and [link to IBM support page].