​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-p836-mcw8-43j4

Published

Last updated

https://images.chainguard.dev/security/CGA-p836-mcw8-43j4
Package

k3d

Latest Update
Fixed
Fixed Version

5.6.0-r11

Aliases
  • CVE-2021-4235
  • GHSA-r88r-gmrh-7j83

Severity

5.5

Medium

CVSS V3

Summary

YAML Go package vulnerable to denial of service

Description

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images