Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40472
HistoryMay 11, 2023 - 4:13 a.m.

Denial Of Service (DoS)

2023-05-1104:13:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
vulnerability
denial of service
out of memory
application crash
archive metadata

0.001 Low

EPSS

Percentile

50.3%

github.com/sigstore/rekor is vulnerable to Denial Of Service (DoS). The vulnerability exists because the archive metadata file size is not checked before the files are read to memory which can lead to out of memory conditions resulting in an application crash.