Potential slowdown / DoS when parsing specially crafted PEM inputs in github.com/cert-manager/cert-manager
{
"url": "https://pkg.go.dev/vuln/GO-2024-3282",
"review_status": "REVIEWED"
}{
"imports": [
{
"symbols": [
"CertificateTemplateFromCSRPEM",
"CertificateTemplateFromCertificateRequest",
"CertificateTemplateFromCertificateSigningRequest",
"DecodePrivateKeyBytes",
"DecodeX509CertificateBytes",
"DecodeX509CertificateChainBytes",
"DecodeX509CertificateRequestBytes",
"DecodeX509CertificateSetBytes",
"GenerateLocallySignedTemporaryCertificate",
"ParseSingleCertificateChainPEM",
"RequestMatchesSpec"
],
"path": "github.com/cert-manager/cert-manager/pkg/util/pki"
},
{
"symbols": [
"OutputFormatDER"
],
"path": "github.com/cert-manager/cert-manager/internal/controller/certificates"
},
{
"symbols": [
"controller.ProcessItem",
"controller.Sync",
"controller.finalizeOrder"
],
"path": "github.com/cert-manager/cert-manager/pkg/controller/acmeorders"
}
]
}