Resource management error in go-getter - CVE-2023-0475
Published: May 10, 2023
Vulnerability identifier: #VU76005
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0475
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when processing archvies. A remote attacker can pass specially crafted archive to the application and perform a denial of service (DoS) attack.
Affected software
go-getter
IBM Cloud Pak for Multicloud Management
OpenShift Security Profiles Operator
IBM Cloud Pak for Watson AIOps
IBM Cloud Pak for Multicloud Management
OpenShift Security Profiles Operator
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-0475
Install updates from vendor's website.
go-getter - addressed in versions 1.7.0, 2.2.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
OpenShift Security Profiles Operator - update to 1.7.0
IBM Cloud Pak for Watson AIOps - update to 4.5.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
OpenShift Security Profiles Operator - update to 1.7.0
IBM Cloud Pak for Watson AIOps - update to 4.5.0