[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2303 --- amazon-ssm-agent

ID: oval:org.secpod.oval:def:1701863Date: (C)2023-11-24   (M)2024-02-26
Class: PATCHFamily: unix




The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server. http2/hpack: avoid quadratic complexity in hpack decoding Templates did not properly consider backticks as Javascript string delimiters, and as such didnot escape them as expected. Backticks are used, since ES6, for JS template literals. If a templatecontained a Go template action within a Javascript template literal, the contents of the action couldbe used to terminate the literal, injecting arbitrary Javascript code into the Go template

Platform:
Amazon Linux 2
Product:
amazon-ssm-agent
Reference:
ALAS2-2023-2303
CVE-2021-43565
CVE-2022-41723
CVE-2023-24538
CVE-2023-29406
CVE-2023-3978
CVE-2023-24540
CVE-2023-29409
CVE    7
CVE-2021-43565
CVE-2023-29406
CVE-2023-3978
CVE-2023-24540
...
CPE    1
cpe:/o:amazon:linux:2

© SecPod Technologies