Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1962

Опубликовано: 12 июл. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

A flaw was found in the golang standard library, go/parser. When calling any Parse functions on the Go source code, which contains deeply nested types or declarations, a panic can occur due to stack exhaustion. This issue allows an attacker to impact system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel8Not affected
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Not affected
Cost Management Metrics Operatorcostmanagement/costmanagement-metrics-rhel8-operatorNot affected
Cryostat 2cryostat-tech-preview/cryostat-rhel8-operatorFix deferred
Fence Agents Remediation Operatorworkload-availability/fence-agents-remediation-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Logical Volume Manager Storagelvms4/topolvm-rhel9Not affected
Machine Deletion Remediation Operatorworkload-availability/machine-deletion-remediation-rhel8-operatorNot affected
Migration Toolkit for Containersrhmtc/openshift-migration-registry-rhel8Affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-api-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1325
https://bugzilla.redhat.com/show_bug.cgi?id=2107376golang: go/parser: stack exhaustion in all Parse* functions

EPSS

Процентиль: 0%
0.00004
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

CVSS3: 5.5
nvd
почти 3 года назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

CVSS3: 5.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 5.5
debian
почти 3 года назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1 ...

CVSS3: 5.5
github
почти 3 года назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

EPSS

Процентиль: 0%
0.00004
Низкий

5.5 Medium

CVSS3