Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVEs in NSM dependencies #7433

Closed
denis-tingaikin opened this issue Sep 23, 2022 · 3 comments
Closed

CVEs in NSM dependencies #7433

denis-tingaikin opened this issue Sep 23, 2022 · 3 comments
Assignees
Labels
bug Something isn't working

Comments

@denis-tingaikin
Copy link
Member

From Giang Tran

CVE-2022-28946: An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.
CVE-2022-33082: An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
In NSC:
CVE-2022-27191: The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
CVE-2021-44716: net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

We should check these CVEs in NSM deps.

@denis-tingaikin denis-tingaikin added the bug Something isn't working label Sep 23, 2022
@ThetaDR
Copy link
Contributor

ThetaDR commented Sep 26, 2022

Checked the repositories for this vulnerabilities - the dependencies are either newer or we don't have them.

@denis-tingaikin
Copy link
Member Author

Fixed by networkservicemesh/sdk-k8s#405

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: Done
Development

No branches or pull requests

2 participants