Improper resource allocation In rh-podman-desktop
Description
A flaw was found in devalue, a JavaScript library used for serializing values. Due to quirks in some JavaScript engines, the devalue.parse function could be exploited by a remote attacker when deserializing specially crafted sparse arrays. This could lead to excessive memory consumption, resulting in a Denial of Service (DoS) for the affected system.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 5.8.1 | ||
rpm rhel10 | 0:1.1.2-1.el10_2 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.