CVE-2021-33580
Dashboard / Vulnerabilities / CVE-2021-33580
CVE-2021-33580
Published: 18 Aug 2021Last Modified: 8 Jul 2026
Summary:
Details: User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. Since the attacker controls the string and the regex pattern he may cause a ReDoS by regex catastrophic backtracking on the server side. This problem has been fixed in Roller 6.0.2.
References: http://www.openwall.com/lists/oss-security/2021/08/18/1, https://lists.apache.org/thread.html/r9d967d80af941717573e531db2c7353a90bfd0886e9b5d5d79f75506%40%3Cuser.roller.apache.org%3E
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
roller-6.0.1
roller-6.0.0-rc-3
roller-6.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
