VDB
BDU%3A2025-08606
BDU%3A2025-08606
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость пакета реализации набора стандартов JWE, JWS, JWT go-jose для языка программирования Go, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., ООО «Ред Софт», Red Hat Inc., Сообщество свободного программного обеспечения | openSUSE Tumbleweed, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Micro, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, SUSE Liberty Linux, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Module for Package Hub, OpenSUSE Leap, SUSE Package Hub, SUSE Linux Enterprise Module for Containers, Red Hat Advanced Cluster Security, SUSE Manager Client Tools, go-jose, SUSE Linux Enterprise Module for High Performance Computing |
Timeline
- Jul 17, 2025 CVE Published
References
- https://www.suse.com/security/cve/CVE-2025-27144.html url
- https://github.com/go-jose/go-jose/releases/tag/v4.0.5_x0001_ url
- https://github.com/go-jose/go-jose/security/advisories/GHSA-c6gw-w398-hv78 url
- https://github.com/go-jose/go-jose/commit/99b346cec4e86d102284642c5dcbe9bb0cacfc22_x0001_ url
- https://redos.red-soft.ru/support/secure/uyazvimosti/uyazvimost-consul-cve-2025-27144/?sphrase_id=1076313 advisory
- https://access.redhat.com/security/cve/CVE-2025-27144 advisory