GHSA-2m4x-4q9j-w97g
Dashboard / Vulnerabilities / GHSA-2m4x-4q9j-w97g
GHSA-2m4x-4q9j-w97g
Summary: Denial of service in Open Policy Agent
Details: An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-33082, https://github.com/open-policy-agent/opa/issues/4761, https://github.com/open-policy-agent/opa/issues/4762, https://github.com/open-policy-agent/opa/pull/4701, https://github.com/open-policy-agent/opa/commit/064f6168a8dfebdeb2ea147f7882bb9f5d2b7f67, https://github.com/open-policy-agent/opa, https://github.com/open-policy-agent/opa/blob/598176de326025451025225aca53e85708d5f1db/ast/compile.go#L1224, https://pkg.go.dev/vuln/GO-2022-0574
Affected packages
Package
Name: github.com/open-policy-agent/opa
Purl: pkg:golang/github.com/open-policy-agent/opa
Affected ranges
Type: SEMVER
Events:
