Описание
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.
An improper input validation vulnerability was found in the cipher-base npm package. Missing input type checks in the polyfill of the Node.js createHash
function result in invalid value calculations, hanging and rewinding the hash state, including turning a tagged hash into an untagged hash, for malicious JSON-stringifyable inputs.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Affected | ||
Multicluster Engine for Kubernetes | multicluster-engine/console-mce-rhel9 | Affected | ||
OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel8 | Affected | ||
OpenShift Pipelines | openshift-pipelines/pipelines-hub-api-rhel8 | Affected | ||
OpenShift Pipelines | openshift-pipelines/pipelines-hub-api-rhel9 | Affected | ||
OpenShift Pipelines | openshift-pipelines/pipelines-hub-db-migration-rhel8 | Affected | ||
OpenShift Pipelines | openshift-pipelines/pipelines-hub-db-migration-rhel9 | Affected | ||
OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel8 | Affected | ||
OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel9 | Affected | ||
OpenShift Serverless | openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.
Improper Input Validation vulnerability in cipher-base allows Input Da ...
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
Уязвимость пакета cipher-base программной платформы Node.js, позволяющая нарушителю выполнить произвольный код
EPSS
7.5 High
CVSS3