CVE-2021-3121
Summary
| CVE | CVE-2021-3121 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-11 06:15:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue. |
Risk And Classification
Problem Types: CWE-129
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Third Party Advisory |
| CVE-2021-3121 GoGo Protobuf Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| [skywalking-notifications] 20211018 [GitHub] [skywalking-swck] hanahmily opened a new pull request #37: Fix vulnerabilities | lists.apache.org | ||
| [pulsar-commits] 20210121 [GitHub] [pulsar-client-go] hrsakai opened a new pull request #446: Upgrade gogo/protobuf to 1.3.2 | lists.apache.org | ||
| Comparing v1.3.1...v1.3.2 · gogo/protobuf · GitHub | MISC | github.com | Patch, Third Party Advisory |
| HCSEC-2021-23 - Consul Exposed to Denial of Service in GoGo Protobuf Dependency - Security - HashiCorp Discuss | MISC | discuss.hashicorp.com | |
| skippy peanut butter · gogo/protobuf@b03c65e · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Third Party Advisory |
| [pulsar-commits] 20210122 [GitHub] [pulsar-client-go] hrsakai opened a new pull request #446: Upgrade gogo/protobuf to 1.3.2 | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179912 Debian Security Update for golang-gogoprotobuf (CVE-2021-3121)
- 239212 Red Hat Update for OpenShift Container Platform 4.7.5 (RHSA-2021:1006)
- 239525 Red Hat Update for OpenShift Container Platform 4.8.2 (RHSA-2021:2437)
- 501764 Alpine Linux Security Update for protobuf-c
- 504321 Alpine Linux Security Update for protobuf-c
- 770055 Red Hat OpenShift Container Platform 4.7.5 Security and Bug Fix Update (RHSA-2021:1006)
- 770064 Red Hat OpenShift Container Platform 4.7.0 Packages and Security Update (RHSA-2020:5634)
- 770074 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021:2437)
- 770109 Red Hat OpenShift Container Platform 4.7 Security Update (RHSA-2021-1006)
- 770111 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021-2437)