PT-2023-22778 · Rekor+1 · Rekor+1

Adamkorcz

+1

·

Published

2023-05-03

·

Updated

2024-08-20

·

CVE-2023-30551

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Rekor versions prior to 1.1.1
Description Rekor is an open source software supply chain transparency log that may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verification of a JAR file submitted to Rekor can cause an out of memory crash if files within the META-INF directory of the JAR are sufficiently large. Parsing of an APK file submitted to Rekor can cause an out of memory crash if the .SIGN or .PKGINFO files within the APK are sufficiently large.
Recommendations Update to Rekor version 1.1.1 to resolve the issue. As a temporary workaround, consider restricting the size of files within the META-INF directory of JAR files and the .SIGN and .PKGINFO files within APK files to prevent out of memory crashes. Avoid submitting JAR or APK files with large files in the META-INF directory or .SIGN and .PKGINFO files to Rekor until the issue is resolved.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-30551
GHSA-2H5H-59F5-C5X9
GO-2023-1754
OPENSUSE-SU-2024:12919-1
SUSE-SU-2023:2210-1
SUSE-SU-2023_2210-1

Affected Products

Rekor
Suse