CVE-2023-2253 is a denial-of-service vulnerability affecting Red Hat OpenShift products, including OpenShift API for Data Protection, OpenShift Container Platform, and OpenShift Developer Tools and Services. An authenticated attacker can exploit a flaw in the /v2/_catalog endpoint by providing an excessively large value for the 'n' parameter, leading to the allocation of a massive string array and consuming significant memory. This vulnerability has a CVSS score of 6.5 (Medium) due to its network-based attack vector and high availability impact. Currently, there is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:openshift_api_for_data_protection:-:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-2253
Dec 10, 2024CVE-2023-2253
Oct 8, 2024A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n` causing the allocation of a massive string array possibly causing a denial of service through excessive use of memory.
Jun 13, 2023distribution catalog API endpoint can lead to OOM via malicious user input
May 11, 2023distribution/distribution: DoS from malicious API request
May 9, 2023