Описание
jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-aggregator-rhel8 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-collector-rhel9 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | acmesolver-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | acm-must-gather-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | acm-operator-bundle-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | application-ui-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | cainjector-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | cert-manager-controller-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | cert-manager-webhook-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | cert-policy-controller-container | Fixed | RHEA-2021:0729 | 04.03.2021 |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=1908451jsonparser: GET call can lead to a slice bounds out of range
EPSS
Процентиль: 62%
0.00426
Низкий
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 5 лет назад
jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.
CVSS3: 7.5
nvd
около 5 лет назад
jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.
CVSS3: 7.5
debian
около 5 лет назад
jsonparser 1.0.0 allows attackers to cause a denial of service (panic: ...
EPSS
Процентиль: 62%
0.00426
Низкий
7.5 High
CVSS3