VDB
CVE-2024-10846
CVE-2024-10846
PUBLISHED
CVSS 5.900000095367432 MEDIUM
Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
EPSS 0.02% · 5.7th percentile
Risk Scores
CVSS v3.1
5.900000095367432
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
EPSS Score
0.02%
5.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | compose-spec/compose-go/v2 | 2.1.0, 2.1.0 |
| compose-spec | compose-go | 0, 0 |
Timeline
- Jan 21, 2025 CVE Published
- Jan 23, 2025 PoC Published
- Jan 23, 2025 PoC Published
- Jan 23, 2025 PoC Published
- Jan 24, 2025 EPSS Score
- Feb 2, 2025 Coalition ESS Score
- Feb 8, 2025 EPSS Score
- Feb 23, 2025 EPSS Score
- Mar 11, 2025 EPSS Score
- Mar 26, 2025 EPSS Score
- Apr 10, 2025 EPSS Score
- Apr 25, 2025 EPSS Score
References
- https://github.com/compose-spec/compose-go/security/advisories/GHSA-36gq-35j3-p9r9 url
- https://security.netapp.com/advisory/ntap-20250425-0008/ url
- https://nvd.nist.gov/vuln/detail/CVE-2024-10846 advisory
- https://github.com/docker/compose/issues/12235 url
- https://github.com/compose-spec/compose-go/pull/618 url
- https://github.com/compose-spec/compose-go/pull/703 url
- https://github.com/docker/compose/commit/d239f0f3187a2ed5404c61f83bd5e995c81600ff#diff-33ef32bf6c23acb95f5902d7097b7a1d5128ca061167ec0716715b0b9eeaa5f6R10 url
- https://github.com/compose-spec/compose-go package
- https://security.netapp.com/advisory/ntap-20250425-0008 url