Vulnerability Description
An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openpolicyagent | Open Policy Agent | < 0.42.0 |
References
- https://github.com/open-policy-agent/opa/blob/598176de326025451025225aca53e85708ExploitThird Party Advisory
- https://github.com/open-policy-agent/opa/blob/598176de326025451025225aca53e85708ExploitThird Party Advisory
FAQ
What is CVE-2022-33082?
CVE-2022-33082 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
How severe is CVE-2022-33082?
CVE-2022-33082 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-33082?
Check the references section above for vendor advisories and patch information. Affected products include: Openpolicyagent Open Policy Agent.