HIGH7.5
GHSA-2m4x-4q9j-w97g
Denial of service in Open Policy Agent
Quick fix
GHSA-2m4x-4q9j-w97g — github.com/open-policy-agent/opa: upgrade to the fixed version with the command below.
go get github.com/open-policy-agent/opa@v0.42.0Details
An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/open-policy-agent/opa
Introduced in:
0Fixed in: 0.42.0Fix
go get github.com/open-policy-agent/opa@v0.42.0References
- https://nvd.nist.gov/vuln/detail/CVE-2022-33082[ADVISORY]
- https://github.com/open-policy-agent/opa/issues/4761[WEB]
- https://github.com/open-policy-agent/opa/issues/4762[WEB]
- https://github.com/open-policy-agent/opa/pull/4701[WEB]
- https://github.com/open-policy-agent/opa/commit/064f6168a8dfebdeb2ea147f7882bb9f5d2b7f67[WEB]
- https://github.com/open-policy-agent/opa[PACKAGE]
- https://github.com/open-policy-agent/opa/blob/598176de326025451025225aca53e85708d5f1db/ast/compile.go#L1224[WEB]
- https://pkg.go.dev/vuln/GO-2022-0574[WEB]