{"id":"GHSA-gxhv-3hwf-wjp9","summary":"JSON-Patch Out-of-bounds Write vulnerability","details":"An out of bound write can occur when patching an Openshift object using the `oc patch` functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.","aliases":["CVE-2018-14632","GO-2021-0076"],"modified":"2023-11-01T04:49:00.119671Z","published":"2022-05-13T01:34:31Z","database_specific":{"github_reviewed_at":"2023-02-08T00:27:34Z","nvd_published_at":"2018-09-06T14:29:00Z","cwe_ids":["CWE-787"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14632"},{"type":"WEB","url":"https://github.com/evanphx/json-patch/pull/57"},{"type":"WEB","url":"https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03"},{"type":"WEB","url":"https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03#diff-65c563bba473be9d94ce4d033f74810e"},{"type":"WEB","url":"https://access.redhat.com/errata/RHBA-2018:2652"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2654"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2709"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2906"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2908"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632"},{"type":"PACKAGE","url":"https://github.com/evanphx/json-patch"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2021-0076"}],"affected":[{"package":{"name":"github.com/evanphx/json-patch","ecosystem":"Go","purl":"pkg:golang/github.com/evanphx/json-patch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gxhv-3hwf-wjp9/GHSA-gxhv-3hwf-wjp9.json"}},{"package":{"name":"github.com/evanphx/json-patch","ecosystem":"Go","purl":"pkg:golang/github.com/evanphx/json-patch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.0.1-0.20180525145409-4c9aadca8f89"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gxhv-3hwf-wjp9/GHSA-gxhv-3hwf-wjp9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"}]}