CVE-2021-28667
Summary
| CVE | CVE-2021-28667 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-18 03:15:00 UTC |
| Updated | 2021-03-25 13:44:00 UTC |
| Description | StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name). |
Risk And Classification
Problem Types: CWE-835
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python | Python | All | All | All | All |
| Application | Stackstorm | Stackstorm | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| StackStorm v3.4.1 - Security fix (CVE-2021-28667) - StackStorm | MISC | stackstorm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.