Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Golang
Subscribe
|
Go
Subscribe
|
|
Redhat
Subscribe
|
Acm
Subscribe
Application Interconnect
Subscribe
Ceph Storage
Subscribe
Container Native Virtualization
Subscribe
Devtools
Subscribe
Enterprise Linux
Subscribe
Multicluster Engine
Subscribe
Openshift Custom Metrics Autoscaler
Subscribe
Openshift Secondary Scheduler
Subscribe
Rhmt
Subscribe
Serverless
Subscribe
Service Mesh
Subscribe
Workload Availability Nmo
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52464 | Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag. |
Ubuntu USN |
USN-6038-1 | Go vulnerabilities |
Ubuntu USN |
USN-6038-2 | Go vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat workload Availability Nmo
|
|
| CPEs | cpe:/a:redhat:workload_availability_nmo:4.11::el8 | |
| Vendors & Products |
Redhat workload Availability Node Maintenance
|
Redhat workload Availability Nmo
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
Redhat multicluster Engine |
|
| CPEs | cpe:/a:redhat:acm:2.5::el8 cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 |
|
| Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 |
|
| Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2024-08-03T06:56:13.196Z
Reserved: 2022-05-12T00:00:00
Link: CVE-2022-30633
No data.
Status : Modified
Published: 2022-08-10T20:15:42.210
Modified: 2024-11-21T07:03:04.227
Link: CVE-2022-30633
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN