CVE-2023-2253
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jun 6, 2023
Updated: Jan 7, 2025
CWE ID 770
CWE ID 475
Summary
CVE-2023-2253 is a newly discovered vulnerability affecting the `/v2/_catalog` endpoint in the distribution package of distribution/distribution. The issue arises from a flawed input validation mechanism for the `n` query parameter, which specifies the maximum number of records to be returned. Malicious users can exploit this vulnerability by submitting excessively large values for `n`, leading to the creation of an unwieldy string array. As a result, the server may experience a denial of service due to excessive memory usage.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Red Hat Openshift Container Platform
Affected Vendors
- Red Hat