Логотип exploitDog
bind:CVE-2024-35194
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-35194

Количество 2

Количество 2

nvd логотип

CVE-2024-35194

больше 1 года назад

Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaustion that can be triggered from maliciously created templates. Minder engine uses templating to generate strings for various use cases such as URLs, messages for pull requests, descriptions for advisories. In some cases can the user control both the template and the params for it, and in a subset of these cases, Minder reads the generated template entirely into memory. When Minders templating meets both of these conditions, an attacker is able to generate large enough templates that Minder will exhaust memory and crash. This vulnerability is fixed in 0.0.50.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-crgc-2583-rw27

больше 1 года назад

Stacklok Minder vulnerable to denial of service from maliciously crafted templates

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-35194

Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaustion that can be triggered from maliciously created templates. Minder engine uses templating to generate strings for various use cases such as URLs, messages for pull requests, descriptions for advisories. In some cases can the user control both the template and the params for it, and in a subset of these cases, Minder reads the generated template entirely into memory. When Minders templating meets both of these conditions, an attacker is able to generate large enough templates that Minder will exhaust memory and crash. This vulnerability is fixed in 0.0.50.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-crgc-2583-rw27

Stacklok Minder vulnerable to denial of service from maliciously crafted templates

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу