Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-30551

Опубликовано: 09 мая 2023
Источник: redhat
CVSS3: 7.5

Описание

Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verification of a JAR file submitted to Rekor can cause an out of memory crash if files within the META-INF directory of the JAR are sufficiently large. Parsing of an APK file submitted to Rekor can cause an out of memory crash if the .SIGN or .PKGINFO files within the APK are sufficiently large. The OOM crash has been patched in Rekor version 1.1.1. There are no known workarounds.

A flaw was found in Rekor. Versions prior to 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verification of a JAR file submitted to Rekor can cause an out of memory crash if files within the META-INF directory of the JAR are sufficiently large. Parsing an APK file submitted to Rekor can also cause an out of memory crash if the .SIGN or .PKGINFO files within the APK are sufficiently large. The OOM crash has been patched in Rekor version 1.1.1. There are no known workarounds.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift API for Data Protectionoadp/oadp-velero-plugin-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Not affected
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Enterprise Linux 8container-tools:rhel8/buildahNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/skopeoNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2196656rekor: compressed archives can result in OOM conditions

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verification of a JAR file submitted to Rekor can cause an out of memory crash if files within the META-INF directory of the JAR are sufficiently large. Parsing of an APK file submitted to Rekor can cause an out of memory crash if the .SIGN or .PKGINFO files within the APK are sufficiently large. The OOM crash has been patched in Rekor version 1.1.1. There are no known workarounds.

CVSS3: 7.5
debian
больше 2 лет назад

Rekor is an open source software supply chain transparency log. Rekor ...

suse-cvrf
больше 2 лет назад

Security update for rekor

CVSS3: 7.5
github
почти 3 года назад

Rekor's compressed archives can result in OOM conditions

7.5 High

CVSS3