Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-33082

Опубликовано: 30 июн. 2022
Источник: redhat
CVSS3: 7.5

Описание

An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

A flaw was found in the Open Policy Agent, where it is vulnerable to a denial of service caused by an issue in the AST parser (ast/compile.go). This flaw allows an attacker to cause a denial of service by sending specially-crafted input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/cnf-tests-rhel8Will not fix
Red Hat OpenShift Container Platform 4openshift4/ztp-site-generate-rhel8Affected
Red Hat OpenShift Container Platform 4openshift-security-profiles-operator-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2196440open-policy-agent: possible DoS via crafted input

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
github
больше 3 лет назад

Denial of service in Open Policy Agent

7.5 High

CVSS3