Show plain JSON{"affected_release": [{"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "nodejs-accepts-0:1.3.3-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "nodejs-express-0:4.13.3-4.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "nodejs-mime-db-0:1.23.0-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "nodejs-mime-types-0:2.1.11-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "nodejs-minimatch-0:3.0.2-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "nodejs-negotiator-0:0.6.1-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "nodejs-accepts-0:1.3.3-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "nodejs-express-0:4.13.3-4.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "nodejs-mime-db-0:1.23.0-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "nodejs-mime-types-0:2.1.11-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "nodejs-minimatch-0:3.0.2-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-08-11T00:00:00Z"}, {"advisory": "RHSA-2016:1605", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "nodejs-negotiator-0:0.6.1-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-08-11T00:00:00Z"}], "bugzilla": {"description": "nodejs-negotiator: Regular expression denial-of-service", "id": "1347677", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1347677"}, "csaw": false, "cvss": {"cvss_base_score": "4.3", "cvss_scoring_vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "status": "verified"}, "cwe": "CWE-20", "details": ["A regular expression denial of service flaw was found in Negotiator. An attacker able to make an application using Negotiator to perform matching using a specially crafted glob pattern could cause the application to consume an excessive amount of CPU."], "name": "CVE-2016-1000022", "public_date": "2016-06-16T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-1000022\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-1000022\nhttps://nodesecurity.io/advisories/106"], "threat_severity": "Moderate", "upstream_fix": "nodejs-negotiator 0.6.1"}