CVE-2024-24786
Infinite loop in JSON unmarshaling in google.golang.org/protobuf
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
google.golang.org/protobuf · google.golang.org/protobuf/encoding/protojsongoogle.golang.org/protobuf · google.golang.org/protobuf/internal/encoding/json¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://go.dev/cl/569356https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JDMBHAVSDU2FBDZ45U3A2VLSM35OJ2HU/https://pkg.go.dev/vuln/GO-2024-2611https://security.netapp.com/advisory/ntap-20240517-0002/http://www.openwall.com/lists/oss-security/2024/03/08/4