Skip to main content

Allocation of Resources Without Limits or Throttling

CVE-2023-30551

Severity High
Score 7.5/10

Summary

Rekor is an open-source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out-of-memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verification of a JAR file submitted to Rekor can cause an out-of-memory crash if files within the "META-INF" directory of the JAR are sufficiently large. Parsing of an APK file submitted to Rekor can cause an out-of-memory crash if the ".SIGN" or ".PKGINFO" files within the APK are sufficiently large. Users are advised to upgrade to a fixed version, there are no known workarounds.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-770 - Allocation of Resources Without Limits or Throttling

The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

Advisory Timeline

  • Published