Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4235

Опубликовано: 27 дек. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

A flaw was found in go-yaml. This issue occurs due to unbounded alias chasing, where a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Will not fix
Migration Toolkit for Containersrhmtc/openshift-migration-controller-rhel8Will not fix
Node Maintenance Operatorworkload-availability/node-maintenance-rhel8-operatorNot affected
OpenShift Developer Tools and ServiceshelmNot affected
OpenShift Developer Tools and ServicesodoAffected
OpenShift Pipelinesopenshift-pipelines-clientWill not fix
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/kn-cli-artifacts-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-clientsWill not fix
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2156727go-yaml: Denial of Service in go-yaml

EPSS

Процентиль: 16%
0.00053
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

CVSS3: 5.5
nvd
около 3 лет назад

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

CVSS3: 5.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.5
debian
около 3 лет назад

Due to unbounded alias chasing, a maliciously crafted YAML file can ca ...

CVSS3: 5.5
github
около 3 лет назад

YAML Go package vulnerable to denial of service

EPSS

Процентиль: 16%
0.00053
Низкий

5.5 Medium

CVSS3