Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rpw-2h95-666c

Опубликовано: 01 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package

Impact

The sflow decode package prior to version 3.4.4 does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume huge amounts of memory resulting in a denial of service.

Specific Go Packages Affected

github.com/cloudflare/goflow/v3/decoders/sflow

Patches

Version 3.4.4 contains patches fixing this.

Workarounds

A possible workaround is to not have your goflow collector publicly reachable.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/cloudflare/goflow/v3

go
Затронутые версииВерсия исправления

< 3.4.4

3.4.4

EPSS

Процентиль: 71%
0.00693
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume large amounts of memory resulting in a denial of service.

EPSS

Процентиль: 71%
0.00693
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400