Overview
About vulnerability
kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/json media type has no schema. In openapi3filter/req_resp_decoder.go, the default defaultContentParameterDecoder dereferences mt.Schema.Value without checking whether mt.Schema is nil, even though doc.Validate() accepts the document under OpenAPI 3.0.x and 3.1.x. A single unauthenticated request supplying the parameter value can panic request validation, causing an aborted request with log growth in the common synchronous net/http path or a full process crash in integrations without recovery. This issue is fixed in version 0.144.0.Details
- Affected product:
- Grafana , getkin/kin-openapi , grafana/dataplane/examples , grafana/dataplane/sdata , grafana/grafana-app-sdk , grafana/grafana-aws-sdk , grafana/grafana-azure-sdk-go , grafana/grafana-google-sdk-go , grafana/grafana-plugin-sdk-go , grafana/grafana/apps/alerting/notifications , grafana/grafana/apps/investigation , grafana/grafana/apps/playlist , grafana/grafana/pkg/aggregator , grafana/grafana/pkg/promlib , grafana/kindsys , grafana/sqlds , grafana/thema , influxdata/influxdb-client-go , oapi-codegen/oapi-codegen , scottlepp/go-duck
- Affected packages:
- github.com/getkin/kin-openapi @ 0.125.0 (+46 more)