{
  "threat_severity" : "Important",
  "public_date" : "2024-07-28T00:00:00Z",
  "bugzilla" : {
    "description" : "fast-xml-parser: ReDOS at currency parsing in currency.js",
    "id" : "2300499",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2300499"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.", "A regular expression denial of service (ReDoS) flaw was found in fast-xml-parser in the currency.js script. By sending a specially crafted regex input, a remote attacker could cause a denial of service condition." ],
  "statement" : "Red Hat has decided to rate this vulnerability as Important due to the potential loss of Availability and the low complexity.",
  "affected_release" : [ {
    "product_name" : "Red Hat Developer Hub 1.2 on RHEL 9",
    "release_date" : "2024-08-28T00:00:00Z",
    "advisory" : "RHBA-2024:5958",
    "cpe" : "cpe:/a:redhat:rhdh:1.2::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1.2-136"
  }, {
    "product_name" : "RHEL-9-CNV-4.16",
    "release_date" : "2024-08-06T00:00:00Z",
    "advisory" : "RHSA-2024:5054",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4.16::el9",
    "package" : "container-native-virtualization/kubevirt-console-plugin-rhel9:v4.16.1-107"
  }, {
    "product_name" : "RHODF-4.14-RHEL-9",
    "release_date" : "2024-10-03T00:00:00Z",
    "advisory" : "RHSA-2024:7624",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.14::el9",
    "package" : "odf4/mcg-core-rhel9:v4.14.11-1"
  }, {
    "product_name" : "RHODF-4.16-RHEL-9",
    "release_date" : "2024-09-18T00:00:00Z",
    "advisory" : "RHSA-2024:6755",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/mcg-core-rhel9:v4.16.2-2"
  }, {
    "product_name" : "RHODF-4.17-RHEL-9",
    "release_date" : "2024-10-30T00:00:00Z",
    "advisory" : "RHSA-2024:8676",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/mcg-core-rhel9:v4.17.0-69"
  } ],
  "package_state" : [ {
    "product_name" : "Migration Toolkit for Applications 6",
    "fix_state" : "Will not fix",
    "package_name" : "mta/mta-ui-rhel8",
    "cpe" : "cpe:/a:redhat:migration_toolkit_applications:6"
  }, {
    "product_name" : "Migration Toolkit for Applications 7",
    "fix_state" : "Not affected",
    "package_name" : "mta/mta-ui-rhel9",
    "cpe" : "cpe:/a:redhat:migration_toolkit_applications:7"
  }, {
    "product_name" : "OpenShift Serverless",
    "fix_state" : "Will not fix",
    "package_name" : "fast-xml-parser",
    "cpe" : "cpe:/a:redhat:serverless:1"
  }, {
    "product_name" : "Red Hat Developer Hub",
    "fix_state" : "Not affected",
    "package_name" : "rhdh-operator-container",
    "cpe" : "cpe:/a:redhat:rhdh:1"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "odh-dashboard-container",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "odh-operator-container",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Affected",
    "package_name" : "container-native-virtualization/kubevirt-console-plugin",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-41818\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-41818\nhttps://github.com/NaturalIntelligence/fast-xml-parser/blob/master/src/v5/valueParsers/currency.js#L10\nhttps://github.com/NaturalIntelligence/fast-xml-parser/commit/d0bfe8a3a2813a185f39591bbef222212d856164\nhttps://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-mpg4-rc92-vx8v" ],
  "name" : "CVE-2024-41818",
  "csaw" : false
}