Junglewise Threat Intelligence

CVE-2021-3822: jsoneditor regular expression denial of service

CVE-2021-3822 · Severity: low · CVSS 3 · Published 2021-09-29

Vendors: npm.

Executive brief

jsoneditor is a web-based JSON editor and validator used to view, edit, and format JSON documents. A regular expression vulnerability in the getInnerText function allows an attacker to provide crafted input that causes the application to consume excessive CPU, potentially making the editor unresponsive and denying service to legitimate users.

Technical details

The vulnerability is a ReDoS (Regular Expression Denial of Service) flaw in the getInnerText function of jsoneditor, caused by an inefficient regular expression used to replace return/newline characters. An unauthenticated attacker over the network can provide specially crafted input that causes the regex engine to enter catastrophic backtracking, consuming excessive CPU and rendering the application unresponsive. No authentication or user interaction is required. The vulnerability was patched in version 9.5.6 with a more efficient regex implementation.

Affected products

  • jsoneditor jsoneditor before 9.5.6

Timeline

  • 2021-09-29: disclosed
  • 2021-09-29: patched: Version 9.5.6 released

References

Related threats