icon

We found results for “

CVE-2022-39213

Good to know:

icon

Date: September 15, 2022

go-cvss is a Go module to manipulate Common Vulnerability Scoring System (CVSS). In affected versions when a full CVSS v2.0 vector string is parsed using "ParseVector", an Out-of-Bounds Read is possible due to a lack of tests. The Go module will then panic. The problem is patched in tag "v0.4.0", by the commit "d9d478ff0c13b8b09ace030db9262f3c2fe031f4". Users are advised to upgrade. Users unable to upgrade may avoid this issue by parsing only CVSS v2.0 vector strings that do not have all attributes defined (e.g. "AV:N/AC:L/Au:N/C:P/I:P/A:C/E:U/RL:OF/RC:C/CDP:MH/TD:H/CR:M/IR:M/AR:M"). As stated in "SECURITY.md" (https://github.com/pandatix/go-cvss/blob/master/SECURITY.md), the CPE v2.3 to refer to this Go module is "cpe:2.3:a:pandatix:go_cvss:*:*:*:*:*:*:*:*". The entry has already been requested to the NVD CPE dictionary.

Language: Go

Severity Score

Severity Score

Weakness Type (CWE)

Out-of-bounds Read

CWE-125

Top Fix

icon

Upgrade Version

Upgrade to version github.com/pandatix/go-cvss - v0.4.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us