Описание
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.
Отчет
RHC package for Red Hat Enterprise Linux 9 mark as Low severity as we do ship the affected code but it's not easily exposed because YAML files are not parsed by RHC.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Not affected | ||
cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-rhel9 | Not affected | ||
Cryostat 2 | cryostat-tech-preview/cryostat-rhel8-operator | Will not fix | ||
Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8 | Not affected | ||
Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-adapter-rhel8 | Not affected | ||
Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-rhel8-operator | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel8-operator | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-proxy-rhel8 | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel8-operator | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/eventrouter-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
Parsing malicious or large YAML documents can consume excessive amount ...
yaml package for Go can consume excessive amounts of CPU or memory
EPSS
7.5 High
CVSS3