Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46402

Опубликовано: 18 нояб. 2023
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

git-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go.

A flaw was found in the git-urls package. This issue occurs when a long input is provided inside the directory path of the git url. This could lead to loading delays or a regular expression denial of service.

Отчет

This vulnerability in the git-urls package requires an attacker to provide malicious input to the git URL parsing function. In Red Hat OpenShift GitOps deployments, git repository URLs are configured exclusively by platform administrators through Application and ApplicationSet custom resources. End users do not have the ability to inject arbitrary git URLs through any exposed API. The attack surface is limited to trusted administrators who already have elevated cluster privileges.

Меры по смягчению последствий

To reduce exposure to this vulnerability in OpenShift GitOps:

  1. Limit Application and ApplicationSet creation to platform administrators using RBAC.
  2. Configure ArgoCD AppProjects with explicit sourceRepos allowlists. Avoid wildcard (*) sources.
  3. Use ApplicationSet resource policies to prevent user-provided git URLs from being templated into Applications.
  4. In order to Audit which Git repositories are used by GitOps and Validate no untrusted repos are configured use: oc get applications -A -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.spec.source.repoURL}{"\n"}{end}'

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Affected
OpenShift Serverlessopenshift-serverless-clientsAffected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Fix deferred
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20

EPSS

Процентиль: 55%
0.0085
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

git-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go.

CVSS3: 7.5
github
почти 3 года назад

Inefficient Regular Expression Complexity in git-urls

EPSS

Процентиль: 55%
0.0085
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2023-46402