Vulnerability Report: GO-2020-0003
- CVE-2020-36568, GHSA-hggr-p7v6-73p5
- Affects: github.com/revel/revel
- Published: Apr 14, 2021
- Modified: May 20, 2024
An attacker can cause an application that accepts slice parameters (https://revel.github.io/manual/parameters.html#slices) to allocate large amounts of memory and crash through manipulating the request query sent to the application.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.0.0all symbols
Aliases
References
- https://github.com/revel/revel/pull/1427
- https://github.com/revel/revel/commit/d160ecb72207824005b19778594cbdc272e8a605
- https://github.com/revel/revel/issues/1424
- https://vuln.go.dev/ID/GO-2020-0003.json
Credits
- @SYM01
Feedback
See anything missing or incorrect?
Suggest an edit to this report.