
We found results for “”
CVE-2022-39213
Good to know:

Date: September 15, 2022
go-cvss is a Go module to manipulate Common Vulnerability Scoring System (CVSS). In affected versions when a full CVSS v2.0 vector string is parsed using "ParseVector", an Out-of-Bounds Read is possible due to a lack of tests. The Go module will then panic. The problem is patched in tag "v0.4.0", by the commit "d9d478ff0c13b8b09ace030db9262f3c2fe031f4". Users are advised to upgrade. Users unable to upgrade may avoid this issue by parsing only CVSS v2.0 vector strings that do not have all attributes defined (e.g. "AV:N/AC:L/Au:N/C:P/I:P/A:C/E:U/RL:OF/RC:C/CDP:MH/TD:H/CR:M/IR:M/AR:M"). As stated in "SECURITY.md" (https://github.com/pandatix/go-cvss/blob/master/SECURITY.md), the CPE v2.3 to refer to this Go module is "cpe:2.3:a:pandatix:go_cvss:*:*:*:*:*:*:*:*". The entry has already been requested to the NVD CPE dictionary.
Language: Go
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Out-of-bounds Read
CWE-125Top Fix

CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |