Allocation of Resources Without Limits or Throttling Affecting kyverno package, versions <1.11.0-r1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-WOLFILATEST-KYVERNO-6064010
  • published16 Nov 2023
  • disclosed20 Feb 2023

Introduced: 20 Feb 2023

CVE-2023-25656  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade Wolfi kyverno to version 1.11.0-r1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kyverno package and not the kyverno package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The application will be killed, and thus availability is impacted. The problem has been patched in the release v1.0.0-rc.3. Some workarounds are available. Users can review their own trust policy file and check if the identity string contains =#. Meanwhile, users should only put trusted certificates in their trust stores referenced by their own trust policy files, and make sure the authenticity validation is set to enforce.

CVSS Scores

version 3.1