CVE-2022-33082: Denial of service in Open Policy Agent
(updated )
An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
References
- github.com/advisories/GHSA-2m4x-4q9j-w97g
- github.com/open-policy-agent/opa/blob/598176de326025451025225aca53e85708d5f1db/ast/compile.go
- github.com/open-policy-agent/opa/commit/064f6168a8dfebdeb2ea147f7882bb9f5d2b7f67
- github.com/open-policy-agent/opa/issues/4761
- github.com/open-policy-agent/opa/issues/4762
- nvd.nist.gov/vuln/detail/CVE-2022-33082
Detect and mitigate CVE-2022-33082 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →