Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
History

Fri, 06 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhmt
CPEs cpe:/a:redhat:openshift_data_foundation:4.14::el9
cpe:/a:redhat:rhmt:1.8::el8
Vendors & Products Redhat rhmt

Mon, 19 May 2025 03:45:00 +0000

Type Values Removed Values Added
Description Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string. Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


Fri, 28 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai:2.16::el8

Thu, 20 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhdh:1.3::el9

Wed, 12 Mar 2025 06:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_data_foundation:4.18::el9

Fri, 14 Feb 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Ai
Redhat rhdh
CPEs cpe:/a:redhat:openshift_ai:2.17::el8
cpe:/a:redhat:rhdh:1.4::el9
Vendors & Products Redhat openshift Ai
Redhat rhdh

Thu, 13 Feb 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat discovery
Redhat openshift Devspaces
Redhat trusted Artifact Signer
CPEs cpe:/a:redhat:openshift_data_foundation:4.15::el9
cpe:/a:redhat:openshift_devspaces:3::el9
cpe:/a:redhat:trusted_artifact_signer:1.1::el9
cpe:/o:redhat:discovery:1.0::el9
Vendors & Products Redhat discovery
Redhat openshift Devspaces
Redhat trusted Artifact Signer

Mon, 23 Dec 2024 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.14::el8

Wed, 18 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.14::el8

Thu, 19 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.14::el8
cpe:/a:redhat:openshift_data_foundation:4.16::el9

Tue, 17 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat trusted Profile Analyzer
CPEs cpe:/a:redhat:trusted_profile_analyzer:1.2::el9
Vendors & Products Redhat trusted Profile Analyzer

Fri, 13 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Data Foundation
CPEs cpe:/a:redhat:openshift_data_foundation:4.17::el9
Vendors & Products Redhat openshift Data Foundation

Thu, 12 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.15::el8
cpe:/a:redhat:openshift:4.16::el9

Tue, 10 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat service Mesh
CPEs cpe:/a:redhat:service_mesh:2.4::el8
cpe:/a:redhat:service_mesh:2.5::el8
Vendors & Products Redhat service Mesh

Wed, 04 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift
CPEs cpe:/a:redhat:openshift:4.17::el9
Vendors & Products Redhat openshift

Tue, 03 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:advanced_cluster_security:4.4::el8

Mon, 02 Dec 2024 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat advanced Cluster Security
CPEs cpe:/a:redhat:advanced_cluster_security:4.5::el8
Vendors & Products Redhat
Redhat advanced Cluster Security

Tue, 26 Nov 2024 03:00:00 +0000

Type Values Removed Values Added
Title cross-spawn: regular expression denial of service
References
Metrics threat_severity

None

threat_severity

Low


Tue, 19 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
References

Fri, 08 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Cross-spawn
Cross-spawn cross-spawn
CPEs cpe:2.3:a:cross-spawn:cross-spawn:*:*:*:*:*:*:*:*
Vendors & Products Cross-spawn
Cross-spawn cross-spawn
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 05:15:00 +0000

Type Values Removed Values Added
Description Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2024-11-08T05:00:04.695Z

Updated: 2025-05-20T14:38:35.942Z

Reserved: 2023-12-22T12:33:20.123Z

Link: CVE-2024-21538

cve-icon Vulnrichment

Updated: 2024-11-08T14:56:53.940Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-08T05:15:06.453

Modified: 2025-05-20T15:16:03.530

Link: CVE-2024-21538

cve-icon Redhat

Severity : Low

Publid Date: 2024-11-08T05:00:04Z

Links: CVE-2024-21538 - Bugzilla