Junglewise Threat Intelligence

CVE-2021-27405: @progfay/scrapbox-parser regular expression denial of service

CVE-2021-27405 · Severity: low · CVSS 3.1 · Published 2021-03-01

Executive brief

@progfay/scrapbox-parser is a Node.js library that parses Scrapbox markup text. A flaw in its regular expression handling allows an attacker to submit specially crafted text with many opening bracket characters that causes the parser to consume excessive CPU resources, degrading application performance or causing service unavailability.

Technical details

This is a regular expression Denial of Service (ReDoS) vulnerability caused by catastrophic backtracking in the parser's regex patterns. An attacker can supply text containing excessive '[' (opening bracket) characters to trigger exponential regex matching behavior, consuming CPU and causing the application to hang or become unresponsive. The vulnerability affects all versions before 6.0.3 and 7.0.x before 7.0.2. The attack requires the ability to provide input to the parser (typically with low privileges required per the CVSS vector), and no user interaction is needed. The issue has been patched in versions 6.0.3 and 7.0.2 or later.

Affected products

  • progfay @progfay/scrapbox-parser before 6.0.3, 7.0.0-7.0.1

Timeline

  • 2021-02-19: disclosed
  • 2021-03-01: advisory
  • 2021-03-01: patched: Versions 6.0.3 and 7.0.2 released

References