AIKIDO-2024-10349

github.com/osteele/liquid is vulnerable to Denial of Service (DoS)

40

Medium

github.com/osteele/liquid go

AIKIDO-2024-10349: github.com/osteele/liquid is vulnerable to Denial of Service (DoS) in versions 0.1.0 - 1.5.0.

Denial of Service (DoS)
Vuln in 0.1.0 - 1.5.0
Fixed in 1.5.1
No CVE available
TL;DR

Affected versions of the package are vulnerable to Denial of Service (DoS) because of a panic when using the 'devided_by' filter with a zero value.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

How can it be fixed?

Upgrade github.com/osteele/liquid library to patch version.

Background info

Link to vendor website

Logo
© 2024 Aikido Security BV | BE0792914919
🇪🇺 Grauwpoort 1, 9000 Ghent, Belgium
🇺🇸 95 Third St, 2nd Fl, San Francisco, CA 94103, US