Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36gq-35j3-p9r9

Опубликовано: 21 янв. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop

Impact

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included

Patches

compose-go v2.24.1 fixed the issue

Workarounds

There isn't any known workaround.

References

Пакеты

Наименование

github.com/compose-spec/compose-go/v2

go
Затронутые версииВерсия исправления

>= 2.1.0, < 2.4.1

2.4.1

EPSS

Процентиль: 8%
0.00031
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

CVSS3: 5.9
nvd
около 1 года назад

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included

CVSS3: 5.9
msrc
11 месяцев назад

Описание отсутствует

suse-cvrf
12 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 8%
0.00031
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-400