Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27813

Опубликовано: 25 авг. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker could use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessknative-servingNot affected
OpenShift Service Mesh 1servicemeshNot affected
OpenShift Service Mesh 1servicemesh-grafanaWill not fix
OpenShift Service Mesh 1servicemesh-operatorNot affected
Red Hat 3scale API Management Platform 23scale-apicast-operator-containerWill not fix
Red Hat 3scale API Management Platform 23scale-operator-containerWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2websocketNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-etcd-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1902111golang-github-gorilla-websocket: integer overflow leads to denial of service

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
nvd
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
debian
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket ...

CVSS3: 7.5
github
больше 4 лет назад

Integer overflow in github.com/gorilla/websocket

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3