CVE-2023-2253
published 2023-06-06CVE-2023-2253: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned…
PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.94%
57.2th percentile
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | docker-registry | < docker-registry 2.8.2+ds1-1 (bookworm) | docker-registry 2.8.2+ds1-1 (bookworm) |
| distribution | distribution | — | — |
| github.com | distribution_distribution | >= 0 < 2.8.2-beta.1+incompatible | 2.8.2-beta.1+incompatible |
| github.com | docker_distribution | >= 0 < 2.8.2-beta.1 | 2.8.2-beta.1 |
| msrc | azl3_containerized-data-importer_1.57.0-14_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cert-manager_1.11.2-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_helm_3.13.2-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
docker-registry vulnerabilities
osv·2023-09-05·CVSS 7.5
CVE-2017-11468 [HIGH] docker-registry vulnerabilities
docker-registry vulnerabilities
It was discovered that Docker Registry incorrectly handled certain crafted
input, A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-11468)
It was discovered that Docker Registry incorrectly handled certain crafted
input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2023-2253)
OSV
CVE-2023-2253: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records retur
osv·2023-06-06·CVSS 6.5
CVE-2023-2253 [MEDIUM] CVE-2023-2253: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records retur
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
OSV
Memory exhaustion in github.com/distribution/distribution
osv·2023-05-24
CVE-2023-2253 Memory exhaustion in github.com/distribution/distribution
Memory exhaustion in github.com/distribution/distribution
Systems that run distribution built after a specific commit running on memory-restricted environments can suffer from denial of service by a crafted malicious /v2/_catalog API endpoint request.
OSV
distribution catalog API endpoint can lead to OOM via malicious user input
osv·2023-05-11
CVE-2023-2253 [HIGH] distribution catalog API endpoint can lead to OOM via malicious user input
distribution catalog API endpoint can lead to OOM via malicious user input
### Impact
Systems that run `distribution` built after a specific commit running on memory-restricted environments can suffer from denial of service by a crafted malicious `/v2/_catalog` API endpoint request.
### Patches
Upgrade to at least 2.8.2-beta.1 if you are running `v2.8.x` release. If you use the code from the main branch, update at least to the commit after [f55a6552b006a381d9167e328808565dd2bf77dc](https://github.com/distribution/distribution/commit/f55a6552b006a381d9167e328808565dd2bf77dc).
### Workarounds
There is no way to work around this issue without patching. Restrict access to the affected API endpoint: see the recommendations section.
### References
`/v2/_catalog` endpoint accepts a parame
GHSA
distribution catalog API endpoint can lead to OOM via malicious user input
ghsa·2023-05-11
CVE-2023-2253 [HIGH] CWE-475 distribution catalog API endpoint can lead to OOM via malicious user input
distribution catalog API endpoint can lead to OOM via malicious user input
### Impact
Systems that run `distribution` built after a specific commit running on memory-restricted environments can suffer from denial of service by a crafted malicious `/v2/_catalog` API endpoint request.
### Patches
Upgrade to at least 2.8.2-beta.1 if you are running `v2.8.x` release. If you use the code from the main branch, update at least to the commit after [f55a6552b006a381d9167e328808565dd2bf77dc](https://github.com/distribution/distribution/commit/f55a6552b006a381d9167e328808565dd2bf77dc).
### Workarounds
There is no way to work around this issue without patching. Restrict access to the affected API endpoint: see the recommendations section.
### References
`/v2/_catalog` endpoint accepts a parame
Ubuntu
Docker Registry vulnerabilities
vendor_ubuntu·2023-09-04·CVSS 7.5
CVE-2023-2253 [HIGH] Docker Registry vulnerabilities
Title: Docker Registry vulnerabilities
Summary: docker-registry could be made to crash if it received specially crafted
input.
It was discovered that Docker Registry incorrectly handled certain crafted
input, which allowed remote attackers to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS. (CVE-2017-11468)
It was discovered that Docker Registry incorrectly handled certain crafted
input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-11468)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows
vendor_msrc·2023-06-13·CVSS 6.5
CVE-2023-2253 [MEDIUM] CWE-770 A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n` causing the allocation of a massive string array possibly causing a denial of service through excessive use of memory.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparenc
Red Hat
distribution/distribution: DoS from malicious API request
vendor_redhat·2023-05-09·CVSS 6.5
CVE-2023-2253 [MEDIUM] CWE-770 distribution/distribution: DoS from malicious API request
distribution/distribution: DoS from malicious API request
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service thr
Debian
CVE-2023-2253: docker-registry - A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, wh...
vendor_debian·2023·CVSS 6.5
CVE-2023-2253 [MEDIUM] CVE-2023-2253: docker-registry - A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, wh...
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
Scope: local
bookworm: resolved (fixed in 2.8.2+ds1-1)
bullseye: resolved (fixed in 2.7.1+ds2-7+deb11u1)
forky: resolved (fixed in 2.8.2+ds1-1)
sid: resolved (fixed in 2.8.2+ds1-1)
trixie: resolved (fixed in 2.8.2+ds1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-06
Published