Race condition in resty - CVE-2023-45286

 

Race condition in resty - CVE-2023-45286

Published: September 17, 2025


Vulnerability identifier: #VU115712
CSH Severity: High
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45286
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a race condition. A remote attacker can exploit the race by calling sync.Pool.Put with the same *bytes.Buffer more than once, when request retries are enabled and a retry occurs, and gain unauthorized access to sensitive information on the system.


Affected software

resty
IBM Fusion HCI
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat Migration Toolkit for Applications

How to mitigate CVE-2023-45286

Install updates from vendor's website.

resty - update to 2.10.0.1
IBM Fusion HCI - update to 2.11.0
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
Red Hat Migration Toolkit for Applications - update to 7.0.3

External References

Related Security Bulletins