VDB

RHSA-2020%3A3780

RHSA-2020%3A3780 PUBLISHED CVSS 7.5 HIGH

A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-cluster-svcat-apiserver-operator@sha256:032aba06e045c1514580674e41047f82af8db63c1be171aed886c137c582d052_amd64 as a component of Red Hat OpenShift Container Platform 4.5*
Red Hatopenshift4/ose-cluster-svcat-apiserver-operator@sha256:16689dfc4918f8fcf5a73a7bbd7c3888f836fbecc820eb3575d474a59d4e18bf_s390x as a component of Red Hat OpenShift Container Platform 4.5openshift4/ose-cluster-svcat-apiserver-operator@sha256:16689dfc4918f8fcf5a73a7bbd7c3888f836fbecc820eb3575d474a59d4e18bf_s390x, *
Red Hatopenshift4/ose-cluster-svcat-apiserver-operator@sha256:62cbc44bdcde5a17f8f0ac60821d2eedd002fb6479e21443d5ce0adb972b9455_ppc64le as a component of Red Hat OpenShift Container Platform 4.5openshift4/ose-cluster-svcat-apiserver-operator@sha256:62cbc44bdcde5a17f8f0ac60821d2eedd002fb6479e21443d5ce0adb972b9455_ppc64le, *
Red Hatopenshift4/ose-cluster-svcat-apiserver-operator@sha256:62cbc44bdcde5a17f8f0ac60821d2eedd002fb6479e21443d5ce0adb972b9455_ppc64le as a component of Red Hat OpenShift Container Platform 4.5openshift4/ose-cluster-svcat-apiserver-operator@sha256:62cbc44bdcde5a17f8f0ac60821d2eedd002fb6479e21443d5ce0adb972b9455_ppc64le
Red Hatopenshift4/ose-cluster-svcat-apiserver-operator@sha256:032aba06e045c1514580674e41047f82af8db63c1be171aed886c137c582d052_amd64 as a component of Red Hat OpenShift Container Platform 4.5openshift4/ose-cluster-svcat-apiserver-operator@sha256:032aba06e045c1514580674e41047f82af8db63c1be171aed886c137c582d052_amd64, *
golang.orgx/text
Red Hatopenshift4/ose-cluster-svcat-apiserver-operator@sha256:16689dfc4918f8fcf5a73a7bbd7c3888f836fbecc820eb3575d474a59d4e18bf_s390x as a component of Red Hat OpenShift Container Platform 4.5*

Timeline

  • Sep 21, 2020 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • May 4, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›