Bug 1212572 - VUL-0: CVE-2022-25883: velociraptor: semver: Versions of the package semver before 7.5.2 are vulnerable to ReDos
Summary: VUL-0: CVE-2022-25883: velociraptor: semver: Versions of the package semver b...
Status: NEW
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Antonio Teixeira
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/370063/
Whiteboard:
Keywords:
Depends on:
Blocks: CVE-2022-25883
  Show dependency treegraph
 
Reported: 2023-06-21 11:28 UTC by Cathy Hu
Modified: 2024-04-08 07:41 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Cathy Hu 2023-06-21 11:31:02 UTC
From a quick scan semver is embedded in the embedded nodejs in velociraptor:

Tracking as affected, please let me know if you think i missed anything:
- SUSE:ALP:Source:Standard:1.0/velociraptor                          0.6.7.5~git81.01be570
- openSUSE:Factory/velociraptor                                      0.6.7.5~git81.01be570

Velociraptor does not have a bugowner in ALP, so assigning to bugowner of security:sensor, please let me know if you are not the right person, then I will reassign.