Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-30153

Опубликовано: 19 мар. 2025
Источник: redhat
CVSS3: 7.5

Описание

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.

A flaw was found in kin-openapi. This vulnerability allows excessive memory consumption via upload of a crafted ZIP file (a "ZIP bomb").

Меры по смягчению последствий

Disable any endpoints in your OpenAPI schema that allows multipart/form-data or allows the uploading of a zipfile.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2flightctlAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-flightctl-api-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-flightctl-periodic-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-flightctl-worker-rhel9Affected
Red Hat Enterprise Linux 10osbuild-composerNot affected
Red Hat Enterprise Linux 8osbuild-composerNot affected
Red Hat Enterprise Linux 9osbuild-composerNot affected
Red Hat OpenShift Container Platform 4o-cloud-hwmgr-plugin-operator-bundle-containerAffected
Red Hat OpenShift Container Platform 4o-cloud-manager-operator-bundle-containerAffected
Red Hat OpenShift Container Platform 4oran-o2ims-operator-bundle-containerAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2353383github.com/getkin/kin-openapi/openapi3filter: Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
6 месяцев назад

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.

CVSS3: 7.5
github
6 месяцев назад

Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter

7.5 High

CVSS3