摘要:
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
安全等级: Low
公告ID: KylinSec-SA-2024-2220
发布日期: 2024年5月27日
关联CVE: CVE-2024-24786
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-24786 | KY3.4-4A | protobuf | Unaffected |
CVE-2024-24786 | KY3.4-5 | protobuf | Unaffected |
CVE-2024-24786 | KY3.5.1 | protobuf | Unaffected |
CVE-2024-24786 | KY3.5.2 | protobuf | Unaffected |