Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxhv-3hwf-wjp9

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

JSON-Patch Out-of-bounds Write vulnerability

An out of bound write can occur when patching an Openshift object using the oc patch functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

Пакеты

Наименование

github.com/evanphx/json-patch

go
Затронутые версииВерсия исправления

< 0.5.2

0.5.2

Наименование

github.com/evanphx/json-patch

go
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.1-0.20180525145409-4c9aadca8f89

3.0.1-0.20180525145409-4c9aadca8f89

EPSS

Процентиль: 65%
0.00486
Низкий

7.7 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 7 лет назад

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

CVSS3: 7.7
redhat
больше 7 лет назад

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

CVSS3: 7.7
nvd
больше 7 лет назад

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

EPSS

Процентиль: 65%
0.00486
Низкий

7.7 High

CVSS3

Дефекты

CWE-787