CVE-2022-3517: High severity Minimatch Project Minimatch Node.js vulnerability
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Other sources
A vulnerability was found in the nodejs-minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
The nodejs-minimatch package versions before 3.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS). It's possible to cause a denial of service when calling the braceExpand function.
References: https://github.com/grafana/grafana-image-renderer/issues/329
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-3517?
CVE-2022-3517 is a vulnerability found in the minimatch package, which allows a Regular Expression Denial of Service (ReDoS).
What is the severity of CVE-2022-3517?
CVE-2022-3517 has a severity rating of high (7/10).
Which software is affected by CVE-2022-3517?
The affected software includes nodejs-minimatch (version up to exclusive 3.0.5) and minimatch (version up to exclusive 3.0.5).
How do I fix CVE-2022-3517?
To fix CVE-2022-3517, update the nodejs-minimatch package to version 3.0.5 or higher.
Where can I find more information about CVE-2022-3517?
You can find more information about CVE-2022-3517 at the following references: - [CVE-2022-3517 on CVE website](https://www.cve.org/CVERecord?id=CVE-2022-3517) - [CVE-2022-3517 on NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-3517) - [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=2134609) - [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:0471)