VDB

CVE-2022-28946

CVE-2022-28946 PUBLISHED CVSS 5 MEDIUM

An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.

EPSS 0.43% · 62.5th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
0.43%
62.5th percentile

Affected Products

VendorProductVersions
n/an/an/a
github.comopen-policy-agent/opa0
Cloudflareaccess
openpolicyagentopen_policy_agent0.39.0

Timeline

  • May 19, 2022 CVE Published
  • May 20, 2022 EPSS Score
  • Jul 7, 2022 EPSS Score
  • Aug 26, 2022 EPSS Score
  • Oct 13, 2022 EPSS Score
  • Dec 1, 2022 EPSS Score
  • Jan 18, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 25, 2023 EPSS Score
  • Jun 12, 2023 EPSS Score
  • Jul 30, 2023 EPSS Score
  • Sep 17, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›