Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.
References
Link | Resource |
---|---|
https://github.com/revel/revel/commit/d160ecb72207824005b19778594cbdc272e8a605 | Patch Third Party Advisory |
https://github.com/revel/revel/issues/1424 | Exploit Third Party Advisory |
https://github.com/revel/revel/pull/1427 | Third Party Advisory |
https://pkg.go.dev/vuln/GO-2020-0003 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-12-27 22:15
Updated : 2024-02-28 19:51
NVD link : CVE-2020-36568
Mitre link : CVE-2020-36568
CVE.ORG link : CVE-2020-36568
JSON object : View
Products Affected
revel
- revel
CWE
CWE-770
Allocation of Resources Without Limits or Throttling