Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38509
HistoryDec 16, 2022 - 3:53 a.m.

Denial Of Service (DoS)

2022-12-1603:53:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
dos
vulnerability
jsonschema.go

0.001 Low

EPSS

Percentile

37.9%

helm.sh/helm/v3 is vulnerable to denial of service. The vulnerability exists because the ValidateAgainstSingleSchema function of jsonschema.go does not properly handle schema validation, allowing an attacker to cause an application crash through null pointer dereference by providing a malicious schema file.