blob: bb78176980a0a525be5a7b0cf65354512e259a10 [file] [log] [blame]
Tatiana Bradleyf1409b02023-05-24 14:02:12 -04001id: GO-2022-0253
Damien Neilb5cb7652022-08-18 15:09:12 -07002modules:
Tatiana Bradley82175fd2023-05-31 17:04:08 -04003 - module: github.com/cloudflare/cfrpki
4 versions:
5 - fixed: 1.4.0
6 vulnerable_at: 1.3.0
7 packages:
8 - package: github.com/cloudflare/cfrpki/sync/lib
9 symbols:
10 - HTTPFetcher.GetXML
Tatiana Bradley7c92a882023-05-08 13:11:54 -040011summary: 'TODO(https://go.dev/issue/56443): fill in summary field'
Damien Neil29d4a652022-07-01 14:53:29 -070012description: |
13 The HTTPFetcher.GetXML function reads a response of unlimited size into
14 memory, permitting resource exhausion.
Damien Neil95a417d2022-08-17 15:39:45 -070015published: 2022-07-15T23:07:48Z
Damien Neil29d4a652022-07-01 14:53:29 -070016cves:
Tatiana Bradley82175fd2023-05-31 17:04:08 -040017 - CVE-2021-3912
Damien Neil29d4a652022-07-01 14:53:29 -070018ghsas:
Tatiana Bradley82175fd2023-05-31 17:04:08 -040019 - GHSA-g9wh-3vrx-r7hg
Tatiana Bradley09108142023-05-18 16:23:32 -040020credits:
Tatiana Bradley82175fd2023-05-31 17:04:08 -040021 - Koen van Hove
Damien Neil00e94d72022-08-26 14:59:35 -070022references:
Tatiana Bradley82175fd2023-05-31 17:04:08 -040023 - fix: https://github.com/cloudflare/cfrpki/commit/648658b1b176a747b52645989cfddc73a81eacad