Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10675

Опубликовано: 09 мар. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.

A flaw was found in golang-github-buger-jsonparser. The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a delete call. The highest threat from this vulnerability is to system availability.

Отчет

The OpenShift Container Platform 4 (OCP) containers, file-integrity-rhel8-operator, cnf-tests-rhel8 and ose-container-networking-plugins-rhel8, do have some references to github.com/buger/jsonparser, mainly in their go.sum files. However, it is not included in the final go build. It is also a dependency of the dependency github.com/containernetworking/plugins which only includes buger/jsonparse when compiling for Windows, which these containers do not. Hence, the associated containers have been marked not affected. OpenShift Virtualization cnv-containernetworking-plugins container depends on github.com/buger/jsonparser only when built for Windows, which it is not, thus it is not affected. Other OpenshiftVirtualization containers (virt-api, virt-controller, virt-handler, virt-launcher, virt-operator, kubernetes-nmstate-handler, ovs-cni-marker, ovs-cni-plugin, kubemacpool, hyperconverged-cluster-operator) have references to github.com/buger/jsonparser, however, it is not included in the final go build.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2jsonparserNot affected
Red Hat OpenShift Container Platform 4openshift4/cnf-tests-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/file-integrity-rhel8-operatorNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-container-networking-plugins-rhel8Not affected
Red Hat OpenShift Virtualization 2cnv-containernetworking-pluginsNot affected
Red Hat OpenShift Virtualization 2hyperconverged-cluster-operatorNot affected
Red Hat OpenShift Virtualization 2kubemacpoolNot affected
Red Hat OpenShift Virtualization 2kubernetes-nmstate-handlerNot affected
Red Hat OpenShift Virtualization 2ovs-cni-markerNot affected
Red Hat OpenShift Virtualization 2ovs-cni-pluginNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1817733golang-github-buger-jsonparser: infinite loop via a Delete call

EPSS

Процентиль: 51%
0.00275
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.

CVSS3: 7.5
nvd
почти 6 лет назад

The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.

CVSS3: 7.5
debian
почти 6 лет назад

The Library API in buger jsonparser through 2019-12-04 allows attacker ...

CVSS3: 7.5
github
больше 4 лет назад

Infinite Loop in jsonparser

EPSS

Процентиль: 51%
0.00275
Низкий

7.5 High

CVSS3