CVE-2021-3121

An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:golang:protobuf:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*

History

01 Apr 2022, 15:41

Type Values Removed Values Added
References (MLIST) https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E - (MLIST) https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E - Mailing List, Third Party Advisory

18 Oct 2021, 06:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E -

14 Sep 2021, 18:49

Type Values Removed Values Added
References (MISC) https://discuss.hashicorp.com/t/hcsec-2021-23-consul-exposed-to-denial-of-service-in-gogo-protobuf-dependency/29025 - (MISC) https://discuss.hashicorp.com/t/hcsec-2021-23-consul-exposed-to-denial-of-service-in-gogo-protobuf-dependency/29025 - Third Party Advisory
CPE cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*

07 Sep 2021, 12:15

Type Values Removed Values Added
References
  • (MISC) https://discuss.hashicorp.com/t/hcsec-2021-23-consul-exposed-to-denial-of-service-in-gogo-protobuf-dependency/29025 -

Information

Published : 2021-01-11 06:15

Updated : 2024-02-04 21:23


NVD link : CVE-2021-3121

Mitre link : CVE-2021-3121

CVE.ORG link : CVE-2021-3121


JSON object : View

Products Affected

hashicorp

  • consul

golang

  • protobuf
CWE
CWE-129

Improper Validation of Array Index