CVE-2023-2253 (Medium) detected in github.com/docker/Cli-v20.10.7+incompatible, github.com/docker/distribution-v2.7.1 #143
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2023-2253 - Medium Severity Vulnerability
Vulnerable Libraries - github.com/docker/Cli-v20.10.7+incompatible, github.com/docker/distribution-v2.7.1
github.com/docker/Cli-v20.10.7+incompatible
The Docker CLI
Library home page: https://proxy.golang.org/github.com/docker/!cli/@v/v20.10.7+incompatible.zip
Path to dependency file: /go.mod
Path to vulnerable library: /go.mod
Dependency Hierarchy:
github.com/docker/distribution-v2.7.1
The toolkit to pack, ship, store, and deliver container content
Library home page: https://proxy.golang.org/github.com/docker/distribution/@v/v2.7.1+incompatible.zip
Path to dependency file: /go.mod
Path to vulnerable library: /go.mod
Dependency Hierarchy:
Found in HEAD commit: df1f7d3f67826e841793324e4796be4fbd91c00f
Found in base branch: main
Vulnerability Details
A flaw was found in the
/v2/_catalog
endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string:n
). This vulnerability allows a malicious user to submit an unreasonably large value forn,
causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.Publish Date: 2023-06-06
URL: CVE-2023-2253
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-hqxw-f8mx-cpmw
Release Date: 2023-04-24
Fix Resolution: v2.8.2
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: