GO-2023-1515
Denial of service when processing Git credentials in github.com/rancher/wrangler
Quick fix
GO-2023-1515 — github.com/rancher/wrangler: upgrade to the fixed version with the command below.
go get github.com/rancher/wrangler@v0.7.4-security1Details
A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources.
This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories.
A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.7.4-security1go get github.com/rancher/wrangler@v0.7.4-security1