Description

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

INFO

Published Date :

2025-02-26T03:07:49.012Z

Last Modified :

2025-02-26T14:46:20.671Z

Source :

Go
AFFECTED PRODUCTS

The following products are affected by CVE-2025-22868 vulnerability.

Vendors Products
Go
  • Jws
Redhat
  • Acm
  • Advanced Cluster Security
  • Cryostat
  • Enterprise Linux
  • Gatekeeper
  • Multicluster Engine
  • Multicluster Globalhub
  • Openshift
  • Openshift Ai
  • Openshift Api Data Protection
  • Openshift Custom Metrics Autoscaler
  • Openshift Data Foundation
  • Openshift Devspaces
  • Openshift Distributed Tracing
  • Openshift Gitops
  • Rhel Eus
  • Rhmt
  • Trusted Artifact Signer
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact