Vulnerability Description
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openpolicyagent | Open Policy Agent | 0.39.0 |
References
- https://github.com/open-policy-agent/opa/commit/e9d3828db670cbe11129885f37f08cbfPatchThird Party Advisory
- https://github.com/open-policy-agent/opa/commit/e9d3828db670cbe11129885f37f08cbfPatchThird Party Advisory
FAQ
What is CVE-2022-28946?
CVE-2022-28946 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range mem...
How severe is CVE-2022-28946?
CVE-2022-28946 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28946?
Check the references section above for vendor advisories and patch information. Affected products include: Openpolicyagent Open Policy Agent.