Tatiana Bradley | f1409b0 | 2023-05-24 14:02:12 -0400 | [diff] [blame] | 1 | id: GO-2022-0253 |
Damien Neil | b5cb765 | 2022-08-18 15:09:12 -0700 | [diff] [blame] | 2 | modules: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame^] | 3 | - module: github.com/cloudflare/cfrpki |
| 4 | versions: |
| 5 | - fixed: 1.4.0 |
| 6 | vulnerable_at: 1.3.0 |
| 7 | packages: |
| 8 | - package: github.com/cloudflare/cfrpki/sync/lib |
| 9 | symbols: |
| 10 | - HTTPFetcher.GetXML |
Tatiana Bradley | 7c92a88 | 2023-05-08 13:11:54 -0400 | [diff] [blame] | 11 | summary: 'TODO(https://go.dev/issue/56443): fill in summary field' |
Damien Neil | 29d4a65 | 2022-07-01 14:53:29 -0700 | [diff] [blame] | 12 | description: | |
| 13 | The HTTPFetcher.GetXML function reads a response of unlimited size into |
| 14 | memory, permitting resource exhausion. |
Damien Neil | 95a417d | 2022-08-17 15:39:45 -0700 | [diff] [blame] | 15 | published: 2022-07-15T23:07:48Z |
Damien Neil | 29d4a65 | 2022-07-01 14:53:29 -0700 | [diff] [blame] | 16 | cves: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame^] | 17 | - CVE-2021-3912 |
Damien Neil | 29d4a65 | 2022-07-01 14:53:29 -0700 | [diff] [blame] | 18 | ghsas: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame^] | 19 | - GHSA-g9wh-3vrx-r7hg |
Tatiana Bradley | 0910814 | 2023-05-18 16:23:32 -0400 | [diff] [blame] | 20 | credits: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame^] | 21 | - Koen van Hove |
Damien Neil | 00e94d7 | 2022-08-26 14:59:35 -0700 | [diff] [blame] | 22 | references: |
Tatiana Bradley | 82175fd | 2023-05-31 17:04:08 -0400 | [diff] [blame^] | 23 | - fix: https://github.com/cloudflare/cfrpki/commit/648658b1b176a747b52645989cfddc73a81eacad |