Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22868

Опубликовано: 26 фев. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

A flaw was found in the golang.org/x/oauth2/jws package in the token parsing component. This vulnerability is made possible because of the use of strings.Split(token, ".") to split JWT tokens, which can lead to excessive memory consumption when processing maliciously crafted tokens with a large number of . characters. An attacker could exploit this functionality by sending numerous malformed tokens and can trigger memory exhaustion and a Denial of Service.

Меры по смягчению последствий

To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to go-jose to check that they do not contain an excessive amount of . characters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager-operator-rhel9Affected
cert-manager Operator for Red Hat OpenShiftjetstack-cert-manager-acmesolver-rhel9Affected
cert-manager Operator for Red Hat OpenShiftjetstack-cert-manager-rhel9Affected
Cryostat 3cryostat-tech-preview/cryostat-storage-rhel8Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-adapter-rhel8Affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Affected
Migration Toolkit for Applications 7mta-dotnet-external-provider-containerWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2348366golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws

EPSS

Процентиль: 20%
0.00063
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
nvd
4 месяца назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
4 месяца назад

An attacker can pass a malicious malformed token which causes unexpect ...

suse-cvrf
3 месяца назад

Security update for restic

EPSS

Процентиль: 20%
0.00063
Низкий

7.5 High

CVSS3

Уязвимость CVE-2025-22868