Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-24535

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.

A flaw was found in the golang implementation of the protobuf protocol. This issue occurs when parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input, which will cause a panic.

Отчет

Red Hat does not include the affected version (v1.29.0) in any of its software.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cost Management Metrics Operatorcostmanagement/costmanagement-metrics-rhel8-operatorNot affected
Cryostat 2cryostat-tech-preview/cryostat-rhel8-operatorNot affected
OpenShift Serverlessopenshift-serverless-1-cliNot affected
OpenShift Serverlessopenshift-serverless-1-eventingNot affected
OpenShift Serverlessopenshift-serverless-1-servingNot affected
Red Hat 3scale API Management Platform 23scale-apicast-operator-bundle-containerNot affected
Red Hat 3scale API Management Platform 23scale-apicast-operator-containerNot affected
Red Hat 3scale API Management Platform 23scale-operator-bundle-containerNot affected
Red Hat 3scale API Management Platform 23scale-operator-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2multicloud-operators-foundationNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2214960golang/Protobuf: panic when parsing an incomplete number

EPSS

Процентиль: 58%
0.0037
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.

CVSS3: 7.5
nvd
больше 2 лет назад

Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.

CVSS3: 7.5
debian
больше 2 лет назад

Parsing invalid messages can panic. Parsing a text-format message whic ...

CVSS3: 7.5
github
почти 3 года назад

google.golang.org/protobuf vulnerable to panic leading to denial of service

EPSS

Процентиль: 58%
0.0037
Низкий

7.5 High

CVSS3