VDB

RHSA-2023%3A5155

RHSA-2023%3A5155 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-pod@sha256:f91bb5e5a544273fc1508d2da76f9c1394cc8741abbffe3f2dd34f5b17a4bfee_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-pod@sha256:f91bb5e5a544273fc1508d2da76f9c1394cc8741abbffe3f2dd34f5b17a4bfee_arm64
Red Hatopenshift4/oc-mirror-plugin-rhel8@sha256:18448bf55ebae86cbca9b2edaa518bc7e6cc7416cb5a826d840f1d871a9ed5a2_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/oc-mirror-plugin-rhel8@sha256:18448bf55ebae86cbca9b2edaa518bc7e6cc7416cb5a826d840f1d871a9ed5a2_amd64
Red Hatopenshift4/ose-docker-registry@sha256:0e358e30d1ed97fdfae528b9bde1cc171c16542b9555716a9615aa22b8cd9a1f_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-docker-registry@sha256:0e358e30d1ed97fdfae528b9bde1cc171c16542b9555716a9615aa22b8cd9a1f_amd64
Red Hatopenshift4/ose-ironic-machine-os-downloader-rhel9@sha256:da3fab642b6bc267453c390e294cf5dc9f2e0a2c97a12bf26c75609e9ad0cf07_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:da3fab642b6bc267453c390e294cf5dc9f2e0a2c97a12bf26c75609e9ad0cf07_arm64
Red Hatopenshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:fbd5516e45f9906ed03417e4413288248610601ae0fa86376ed5eb91ff838d98_s390x as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:fbd5516e45f9906ed03417e4413288248610601ae0fa86376ed5eb91ff838d98_s390x
Red Hatopenshift4/ose-installer@sha256:7b6d0dae52cfbb2d9455e09a04fe5d83795ddb240d7aa603df3de957e2e1ba20_amd64 as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-baremetal-installer-rhel8@sha256:a7dfa2fafdb54914e70964b92ce7de1d5488f2a0fa36cc80be5ec32e87554e71_ppc64le as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-installer-rhel8@sha256:a7dfa2fafdb54914e70964b92ce7de1d5488f2a0fa36cc80be5ec32e87554e71_ppc64le
Red Hatopenshift4/ose-machine-os-images-rhel8@sha256:709e226808cf8193cba40679a8fa160578dbf683542bbdefb47129f4d272ecd0_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-machine-os-images-rhel8@sha256:709e226808cf8193cba40679a8fa160578dbf683542bbdefb47129f4d272ecd0_arm64
Red Hatopenshift4/network-tools-rhel8@sha256:5e23799756752e14904862e2c6615b9bb14d1fcb21df8c9b6a9d3d1a36b2bd9e_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/network-tools-rhel8@sha256:5e23799756752e14904862e2c6615b9bb14d1fcb21df8c9b6a9d3d1a36b2bd9e_amd64
Red Hatopenshift4/ose-operator-marketplace@sha256:780d71203149c8c3188e9d2f3c2530b85d700384f4e0c29165f124965570f3d6_s390x as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-operator-marketplace@sha256:780d71203149c8c3188e9d2f3c2530b85d700384f4e0c29165f124965570f3d6_s390x
Red Hatopenshift4/ose-console-operator@sha256:9b085bbdf4dcdae01e42da6713f8e05a0018382010e25ca994a77ed799fa71f1_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-console-operator@sha256:9b085bbdf4dcdae01e42da6713f8e05a0018382010e25ca994a77ed799fa71f1_arm64
Red Hatopenshift4/ose-vmware-vsphere-csi-driver-operator-rhel8@sha256:649a4597d7935661bfc84946901a199732b652ed6cff5761a290951f0a8ec131_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-vmware-vsphere-csi-driver-operator-rhel8@sha256:649a4597d7935661bfc84946901a199732b652ed6cff5761a290951f0a8ec131_amd64
Red Hatopenshift4/ose-pod@sha256:3eb0334648c6d717a8c07efa84bba72adee9aa91cd150662c7065d35832b58b6_s390x as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-pod@sha256:3eb0334648c6d717a8c07efa84bba72adee9aa91cd150662c7065d35832b58b6_s390x
Red Hatopenshift4/ose-hypershift-rhel8@sha256:618cb1c833cc08e8ab62a73e67148da1bea9faca0d174a0225d5fb1b1e766fbf_s390x as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-hypershift-rhel8@sha256:618cb1c833cc08e8ab62a73e67148da1bea9faca0d174a0225d5fb1b1e766fbf_s390x
Red Hatopenshift4/ose-operator-marketplace@sha256:73963b4138566baa4a01034c4b7315debf58d69bf6f2d2f0d7bf452b8d5ff3ee_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-operator-marketplace@sha256:73963b4138566baa4a01034c4b7315debf58d69bf6f2d2f0d7bf452b8d5ff3ee_arm64
Red Hatopenshift4/ose-ovn-kubernetes@sha256:f2a4293bb7ed88265144feeb0a82414967044cb82a95cd239f88b219ef4b95df_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-ovn-kubernetes@sha256:f2a4293bb7ed88265144feeb0a82414967044cb82a95cd239f88b219ef4b95df_amd64
Red Hatopenshift4/ose-ovn-kubernetes@sha256:9f05cd961c450f2ef6766d859ddedacfc287efad1ea36bd34686752b78eea7dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:df380de574ab4feb933c3cb760dad052e5e5cc10cdfba2f71369d91084ca32f1_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:df380de574ab4feb933c3cb760dad052e5e5cc10cdfba2f71369d91084ca32f1_arm64
Red Hatopenshift4/ose-installer@sha256:d764590d27d76347fe40a426906128393cca110aa19261f4cd3465dab410fc1f_arm64 as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-ovn-kubernetes@sha256:0d6c20000ffae48bb3b529c82d6333a529dec2c63c30c565435054884f8a1b9d_s390x as a component of Red Hat OpenShift Container Platform 4.13*

…and 42 more

Timeline

  • Sep 19, 2023 CVE Published
  • Apr 24, 2026 CVE Updated
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›