An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
History

Fri, 04 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.4
Vendors & Products Redhat rhel Eus

Wed, 02 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat cryostat
CPEs cpe:/a:redhat:cryostat:4::el9
Vendors & Products Redhat cryostat

Wed, 02 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat multicluster Globalhub
Redhat openshift Custom Metrics Autoscaler
CPEs cpe:/a:redhat:multicluster_globalhub:1.2::el9
cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.15::el9
Vendors & Products Redhat multicluster Globalhub
Redhat openshift Custom Metrics Autoscaler

Fri, 28 Mar 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat enterprise Linux

Wed, 26 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat acm
CPEs cpe:/a:redhat:acm:2.13::el9
Vendors & Products Redhat acm

Thu, 20 Mar 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat gatekeeper
CPEs cpe:/a:redhat:gatekeeper:3.15::el9
cpe:/a:redhat:gatekeeper:3.17::el9
Vendors & Products Redhat gatekeeper

Tue, 11 Mar 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat advanced Cluster Security
CPEs cpe:/a:redhat:advanced_cluster_security:4.5::el8
cpe:/a:redhat:advanced_cluster_security:4.6::el8
Vendors & Products Redhat
Redhat advanced Cluster Security

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Feb 2025 02:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1286
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 26 Feb 2025 03:15:00 +0000

Type Values Removed Values Added
Description An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
Title Unexpected memory consumption during token parsing in golang.org/x/oauth2
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2025-02-26T14:46:20.671Z

Reserved: 2025-01-08T19:11:42.834Z

Link: CVE-2025-22868

cve-icon Vulnrichment

Updated: 2025-02-26T14:45:55.061Z

cve-icon NVD

Status : Received

Published: 2025-02-26T08:14:24.897

Modified: 2025-02-26T15:15:24.993

Link: CVE-2025-22868

cve-icon Redhat

Severity : Important

Publid Date: 2025-02-26T03:07:49Z

Links: CVE-2025-22868 - Bugzilla