Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1qcjc3LThneDQtaDVxaM4AAv0s
MessagePack for Golang subject to DoS via Unmarshal panic
Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. This issue has been patched in version 2.1.1.
Permalink: https://github.com/advisories/GHSA-jr77-8gx4-h5qhJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcjc3LThneDQtaDVxaM4AAv0s
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 1 year ago
Updated: 8 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Identifiers: GHSA-jr77-8gx4-h5qh, CVE-2022-41719
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-41719
- https://github.com/shamaton/msgpack/issues/31
- https://github.com/shamaton/msgpack/pull/32
- https://pkg.go.dev/vuln/GO-2022-0972
- https://github.com/shamaton/msgpack/releases/tag/v2.1.1
- https://github.com/advisories/GHSA-jr77-8gx4-h5qh
Blast Radius: 8.1
Affected Packages
go:github.com/shamaton/msgpack/v2
Dependent packages: 36Dependent repositories: 12
Downloads:
Affected Version Ranges: < 2.1.1
Fixed in: 2.1.1
All affected versions: 2.0.0, 2.0.1, 2.0.2, 2.1.0
All unaffected versions: 2.1.1