Junglewise Threat Intelligence

CVE-2021-4306: terminal-kit inefficient regular expression complexity

CVE-2021-4306 · Severity: low · CVSS 3.1 · Published 2023-01-07

Vendors: npm.

Executive brief

terminal-kit is a popular Node.js library for creating interactive terminal interfaces and styling console output. An inefficient regular expression pattern can be exploited to cause a denial-of-service attack, making applications using this library unresponsive when processing specially crafted input. This vulnerability affects applications that render user-controlled text or accept dynamic terminal input.

Technical details

The vulnerability is a ReDoS (Regular Expression Denial of Service) issue caused by inefficient regular expression complexity in terminal-kit versions up to 2.1.7. The library uses a problematic regex pattern that exhibits catastrophic backtracking when matching certain inputs, allowing an attacker to craft malicious strings that consume excessive CPU resources and cause the application to hang. The vulnerability is classified as CWE-1333 (inefficient regular expression complexity). An attacker can trigger this via network or local input without authentication. The fix was applied in version 2.1.8 via commit a2e446cc3927b559d0281683feb9b821e83b754c.

Affected products

  • cronvel terminal-kit up to 2.1.7

Timeline

  • 2023-01-07: disclosed
  • 2023-01-12: patched: Fixed in version 2.1.8

References