Vulnerability Name: | CVE-2022-41715 (CCN-240559) | ||||||||||||||||||||||||||||
Assigned: | 2022-10-04 | ||||||||||||||||||||||||||||
Published: | 2022-10-04 | ||||||||||||||||||||||||||||
Updated: | 2023-03-03 | ||||||||||||||||||||||||||||
Summary: | Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-41715 Source: XF Type: UNKNOWN golang-cve202241715-dos(240559) Source: security@golang.org Type: Patch security@golang.org Source: security@golang.org Type: Issue Tracking, Third Party Advisory security@golang.org Source: CCN Type: Golang Web page Go 1.19.2 and Go 1.18.7 are released Source: security@golang.org Type: Mailing List, Release Notes security@golang.org Source: security@golang.org Type: Vendor Advisory security@golang.org Source: CCN Type: IBM Security Bulletin 6852715 (Cloud Pak for Integration) Operations Dashboard is vulnerable to multiple Go CVEs Source: CCN Type: IBM Security Bulletin 6857853 (App Connect Enterprise Certified Container) IBM App Connect Enterprise Certified Container operator and operands may be vulnerable to denial of service due to [CVE-2022-41715] Source: CCN Type: IBM Security Bulletin 6890851 (Watson Speech Services Cartridge for Cloud Pak for Data) IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to a denial of service in Golang Go (CVE-2022-41715) Source: CCN Type: IBM Security Bulletin 6891055 (Cloud Integration Platform) Platform Navigator and Automation Assets in IBM Cloud Pak for Integration is vulnerable to multiple Go vulnerabilities Source: CCN Type: IBM Security Bulletin 6955849 (Decision Optimization for Cloud Pak for Data) Multiple vulnerabilities in Golang Go affect IBM Decision Optimization in IBM Cloud Pak for Data Source: CCN Type: IBM Security Bulletin 6955929 (Watson Discovery) IBM Watson Discovery Cartridge for IBM Cloud Pak for Data affected by vulnerability in Golang Go Source: CCN Type: IBM Security Bulletin 6958146 (Cloud Pak for Watson AIOps) Multiple Vulnerabilities in CloudPak for Watson AIOPs Source: CCN Type: IBM Security Bulletin 6963940 (CICS TX Advanced) CVE-2022-2879, CVE-2022-41715, CVE-2022-2880, CVE-2022-41717, CVE-2022-41716 may affect IBM CICS TX Advanced Source: CCN Type: IBM Security Bulletin 6963942 (CICS TX Standard) CVE-2022-2879, CVE-2022-41715, CVE-2022-2880, CVE-2022-41717, CVE-2022-41716 may affect IBM CICS TX Standard Source: CCN Type: IBM Security Bulletin 6965816 (Spectrum Protect Plus) Vulnerabilities in Node.js, libcurl, Golang Go, Jetty, Guava, Netty, OpenSSL, Linux kernel may affect IBM Spectrum Protect Plus Source: CCN Type: IBM Security Bulletin 6966998 (WebSphere Automation) Multiple vulnerabilities in the mongo-tools utility affect IBM WebSphere Automation Source: CCN Type: IBM Security Bulletin 6983270 (Robotic Process Automation) Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. Source: CCN Type: IBM Security Bulletin 6986361 (Robotic Process Automation) Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. Source: CCN Type: IBM Security Bulletin 7008407 (Robotic Process Automation for Cloud Pak) Multiple operator framework security vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak Source: CCN Type: IBM Security Bulletin 7009921 (Watson Assistant for Cloud Pak for Data) IBM Watson Assistant for IBM Cloud Pak for Data is affected by multiple vulnerabilities in Golang Go Source: CCN Type: IBM Security Bulletin 7012675 (Netcool Operations Insight) Netcool Operations Insights 1.6.9 addresses multiple security vulnerabilities. Source: CCN Type: Mend Vulnerability Database CVE-2022-41715 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |