CVE-2024-10846 DetailsANALYZED This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.
Description The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included
A denial-of-service vulnerability has been identified in the Compose-Go library, specifically in versions 2.10 through 2.4.0. This vulnerability allows an authorized user to send malicious YAML payloads that cause the library to excessively consume memory and CPU resources while parsing the YAML. This issue affects Docker Compose versions 2.27.0 to 2.29.7.
Users can upgrade to Compose-Go version 2.4.1, which addresses this vulnerability.
Show AI summary Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 23, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Partial
CISA-ADP
Assessed Feb 12, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration Affected Products Product Versions compose-spec/compose-go All versions
CPE No CPEs found in CPE dictionary for this product. Remediation No remediation found in references. NetApp All versions
CPE cpe:2.3:a:netapp:active_iq:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:astra_trident:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:data_ontap:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:data_ontap:*:*:*:*:*:7-mode:*:* cpe:2.3:a:netapp:e-series_santricity_unified_manager:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:hyper_converged_infrastructure:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_9:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:santricity_unified_manager:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:system_manager:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:virtual_storage_console:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:500f:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a220:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a250:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a320:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a400:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a800:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_500f:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_a700s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:affa900:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:c250:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:c400:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fabric-attached_storage_8300:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fabric-attached_storage_8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fabric-attached_storage_a400:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas2600:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas26x0:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas2720:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas27x0:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas9000:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas9500:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300e:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410c:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h610s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h615c:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700e:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:data_ontap:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:storagegrid_firmware:*:*:*:*:*:*:*:* Remediation No remediation found in references.
Change History 4 change records found show changes