Resource exhaustion in yaml - CVE-2021-4235

 

Resource exhaustion in yaml - CVE-2021-4235

Published: January 19, 2023 / Updated: February 8, 2023


Vulnerability identifier: #VU71361
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-4235
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing YAML files. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

yaml
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Ansible Automation Platform
Red Hat Migration Toolkit for Applications
IBM Fusion HCI
Ubuntu
golang-yaml.v2-dev (Ubuntu package)
golang-gopkg-yaml.v2-dev (Ubuntu package)
Planning Analytics Connector for SAP
IBM Cloud Pak for Watson AIOps
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2021-4235

Install updates from vendor's website.

yaml - update to 2.2.3
Migration Toolkit for Containers - addressed in versions 1.7.7, 1.7.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.0, 4.12.2, 4.12.22, 4.13.0
Red Hat Migration Toolkit for Applications - update to 6.1.0
golang-yaml.v2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.2-1ubuntu0.1
golang-gopkg-yaml.v2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.2-1ubuntu0.1
Planning Analytics Connector for SAP - update to 1.0 IF1
OpenShift Service Mesh - update to 2.4.0
IBM Fusion HCI - update to 2.6.1
IBM Cloud Pak for Watson AIOps - update to 4.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0

External References

Related Security Bulletins