Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38561

Опубликовано: 12 авг. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

A flaw was found in golang. The language package for go language can panic due to an out-of-bounds read when an incorrectly formatted language tag is being parsed. This flaw allows an attacker to cause applications using this package to parse untrusted input data to crash, leading to a denial of service of the affected component.

Отчет

This flaw may be triggered only by accepting untrusted user input to the vulnerable golang's library. The overall DoS attack vector depends directly on how the library's input is exposed by the consuming application, thus Red Hat rates impact as Moderate. In Red Hat Advanced Cluster Management for Kubernetes (RHACM) 2.5 version, the registration-operator, lighthouse-coredns, lighthouse-agent, gatekeeper-operator, and discovery-operator components are affected by this flaw, but the rest of the components are using an already patched version and are unaffected. For 2.4 and previous versions of Red Hat Advanced Cluster Management for Kubernetes (RHACM), most of the components are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel8Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-controller-rhel8Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-velero-restic-restore-helper-rhel8Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-velero-rhel8Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-must-gather-api-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-velero-restic-restore-helper-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-velero-rhel8Not affected
OpenShift Developer Tools and ServicesodoFix deferred
OpenShift Service Mesh 2.0servicemeshAffected
OpenShift Service Mesh 2.0servicemesh-cniAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2100495golang: out-of-bounds read in golang.org/x/text/language leads to DoS

EPSS

Процентиль: 17%
0.00053
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

CVSS3: 7.5
nvd
около 3 лет назад

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
около 3 лет назад

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic ...

CVSS3: 7.5
github
около 3 лет назад

golang.org/x/text/language Out-of-bounds Read vulnerability

EPSS

Процентиль: 17%
0.00053
Низкий

7.5 High

CVSS3

Уязвимость CVE-2021-38561