Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-4235

Опубликовано: 27 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

РелизСтатусПримечание
bionic

DNE

devel

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

focal

ignored

end of standard support, was needed
jammy

needed

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

2.2.3
esm-apps/jammy

not-affected

2.2.3
esm-apps/noble

not-affected

2.2.3
esm-infra/focal

DNE

focal

DNE

jammy

not-affected

2.2.3
kinetic

ignored

end of life, was needs-triage
lunar

not-affected

2.2.3
mantic

not-affected

2.2.3

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

2.2.8-1
esm-apps/bionic

released

0.0+git20170407.0.cd8b52f-1ubuntu2+esm1
esm-apps/focal

released

2.2.2-1ubuntu0.1
esm-apps/jammy

not-affected

2.2.8-1
esm-apps/noble

not-affected

2.2.8-1
esm-infra/xenial

released

0.0+git20160301.0.a83829b-1ubuntu0.1~esm1
focal

released

2.2.2-1ubuntu0.1
jammy

not-affected

2.2.8-1
kinetic

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
focal

ignored

end of standard support, was needs-triage
jammy

not-affected

code not present
kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

kinetic

DNE

noble

needs-triage

oracular

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 16%
0.00053
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
около 3 лет назад

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

CVSS3: 5.5
nvd
около 3 лет назад

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

CVSS3: 5.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.5
debian
около 3 лет назад

Due to unbounded alias chasing, a maliciously crafted YAML file can ca ...

CVSS3: 5.5
github
около 3 лет назад

YAML Go package vulnerable to denial of service

EPSS

Процентиль: 16%
0.00053
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2021-4235