Логотип exploitDog
bind:"CVE-2023-45290" OR bind:"CVE-2024-28180" OR bind:"CVE-2024-28176"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-45290" OR bind:"CVE-2024-28180" OR bind:"CVE-2024-28176"

Количество 70

Количество 70

rocky логотип

RLSA-2024:3827

больше 1 года назад

Moderate: buildah security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2024:3826

больше 1 года назад

Moderate: podman security and bug fix update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3827

больше 1 года назад

ELSA-2024-3827: buildah security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3826

больше 1 года назад

ELSA-2024-3826: podman security and bug fix update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:3968

больше 1 года назад

Moderate: container-tools:rhel8 bug fix and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3968

больше 1 года назад

ELSA-2024-3968: container-tools:ol8 bug fix and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2023-45290

почти 2 года назад

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-45290

почти 2 года назад

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-45290

почти 2 года назад

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-45290

3 месяца назад

Memory exhaustion in multipart form parsing in net/textproto and net/http

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-45290

почти 2 года назад

When parsing a multipart form (either explicitly with Request.ParseMul ...

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2024:3830

больше 1 года назад

Moderate: gvisor-tap-vsock security and bug fix update

EPSS: Низкий
github логотип

GHSA-rr6r-cfgf-gc6h

почти 2 года назад

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-3831

больше 1 года назад

ELSA-2024-3831: containernetworking-plugins security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3830

больше 1 года назад

ELSA-2024-3830: gvisor-tap-vsock security and bug fix update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-02047

почти 2 года назад

Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю вызвать отказ в обслуживании (DoS)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-28176

почти 2 года назад

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2024-28176

почти 2 года назад

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-28176

почти 2 года назад

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2024-28180

почти 2 года назад

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:3827

Moderate: buildah security and bug fix update

больше 1 года назад
rocky логотип
RLSA-2024:3826

Moderate: podman security and bug fix update

больше 1 года назад
oracle-oval логотип
ELSA-2024-3827

ELSA-2024-3827: buildah security and bug fix update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-3826

ELSA-2024-3826: podman security and bug fix update (MODERATE)

больше 1 года назад
rocky логотип
RLSA-2024:3968

Moderate: container-tools:rhel8 bug fix and enhancement update

больше 1 года назад
oracle-oval логотип
ELSA-2024-3968

ELSA-2024-3968: container-tools:ol8 bug fix and enhancement update (MODERATE)

больше 1 года назад
ubuntu логотип
CVE-2023-45290

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2023-45290

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-45290

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-45290

Memory exhaustion in multipart form parsing in net/textproto and net/http

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2023-45290

When parsing a multipart form (either explicitly with Request.ParseMul ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад
rocky логотип
RLSA-2024:3830

Moderate: gvisor-tap-vsock security and bug fix update

0%
Низкий
больше 1 года назад
github логотип
GHSA-rr6r-cfgf-gc6h

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
oracle-oval логотип
ELSA-2024-3831

ELSA-2024-3831: containernetworking-plugins security and bug fix update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-3830

ELSA-2024-3830: gvisor-tap-vsock security and bug fix update (MODERATE)

больше 1 года назад
fstec логотип
BDU:2024-02047

Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю вызвать отказ в обслуживании (DoS)

CVSS3: 7.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
4%
Низкий
почти 2 года назад

Уязвимостей на страницу