PT-2024-28769 · Go-Chart · Go-Chart

F3Ig0N9

·

Published

2024-07-23

·

Updated

2024-11-01

·

CVE-2024-40060

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions go-chart version 2.1.1
Description The issue is related to an infinite loop in the drawCanvas() function. This function is part of the go-chart library and is used for rendering charts. The infinite loop can cause the program to consume excessive resources, leading to potential denial-of-service conditions.
Recommendations For go-chart version 2.1.1, consider disabling the drawCanvas() function until a patch is available to prevent potential exploitation. Restrict access to the drawCanvas() function to minimize the risk of excessive resource consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2024-40060

Affected Products

Go-Chart