A denial of services (DoS) vulnerability was discovered in Wrangler Git package affecting versions up to and including v1.0.0
.
Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories.
A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version.
Patched versions include v1.0.1
and later and the backported tags - v0.7.4-security1
, v0.8.5-security1
and v0.8.11
.
If you have any questions or comments about this advisory:
{ "nvd_published_at": "2023-02-07T13:15:00Z", "github_reviewed_at": "2023-01-25T19:40:26Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-150", "CWE-74" ] }