VDB
Sign up
—

GO-2023-1515

Denial of service when processing Git credentials in github.com/rancher/wrangler

Quick fix

GO-2023-1515 — github.com/rancher/wrangler: upgrade to the fixed version with the command below.

go get github.com/rancher/wrangler@v0.7.4-security1

Details

A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources.

This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories.

A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/rancher/wrangler
Introduced in: 0Fixed in: 0.7.4-security1
Fixgo get github.com/rancher/wrangler@v0.7.4-security1

References