Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39656
HistoryMar 11, 2023 - 4:17 p.m.

Denial Of Service (DoS)

2023-03-1116:17:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
denial of service
vulnerability
github.com/crossplane/crossplane-runtime
pave function
setvalue function
excessive memory

0.001 Low

EPSS

Percentile

37.9%

github.com/crossplane/crossplane-runtime is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the Pave and setValue functions in paved.go because it does not enforce the max index size of a field path, allowing an attacker to use excessive memory and cause an application crash.

0.001 Low

EPSS

Percentile

37.9%

Related for VERACODE:39656