7.5
CVSSv3

CVE-2020-28362

Published: 18/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Go prior to 1.14.12 and 1.15.x prior to 1.15.4 allows Denial of Service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go

fedoraproject fedora 32

fedoraproject fedora 33

netapp trident -

netapp cloud insights telegraf agent -

Vendor Advisories

Go before 11412 and 115x before 1154 allows Denial of Service (CVE-2020-28362) Go before 11412 and 115x before 1155 allows Code Injection (CVE-2020-28366) Go before 11412 and 115x before 1155 allows Argument Injection (CVE-2020-28367) ...
Synopsis Moderate: go-toolset-114-golang security update Type/Severity Security Advisory: Moderate Topic An update for go-toolset-114-golang is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scor ...
Synopsis Moderate: Red Hat OpenShift Serverless Client kn 1120 Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Serverless Client kn 1120Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score,which g ...
Synopsis Moderate: OpenShift Container Platform 46 file-integrity-operator image security update Type/Severity Security Advisory: Moderate Topic A new file-integrity-operator image update is now available for OpenShift Container Platform 46Red Hat Product Security has rated this update as having a securi ...
Synopsis Important: OpenShift Container Platform 4612 packages and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4612 is now available withupdates to packages and images that fix several bugsThis release includes a security update for Red ...
Synopsis Moderate: go-toolset:rhel8 security update Type/Severity Security Advisory: Moderate Topic An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
Synopsis Moderate: OpenShift Container Platform 4612 extras and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4612 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has ra ...
Synopsis Moderate: OpenShift Container Platform 46 compliance-operator security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for compliance-content-container, ose-compliance-openscap-container, ose-compliance-operator-container, and ose-compliance-operator-metadata-container ...
Synopsis Moderate: OpenShift Container Platform 4612 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4612 is now available withupdates to packages and images that fix several bugsThis release includes a security update for Red Hat ...
Synopsis Moderate: Release of OpenShift Serverless 1120 Type/Severity Security Advisory: Moderate Topic Release of OpenShift Serverless 1120Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score,which gives a detaile ...
Go before 11412 and 115x before 1154 allows Denial of Service (CVE-2020-28362) Go before 11412 and 115x before 1155 allows Code Injection (CVE-2020-28366) Go before 11412 and 115x before 1155 allows Argument Injection (CVE-2020-28367) ...
A flaw was found in go before 1155 where a number of math/bigInt methods (Div, Exp, DivMod, Quo, Rem, QuoRem, Mod, ModInverse, ModSqrt, Jacobi, and GCD) can panic when provided crafted large inputs For the panic to happen, the divisor or modulo argument must be larger than 3168 bits (on 32-bit architectures) or 6336 bits (on 64-bit architecture ...