First published: Thu Mar 18 2021(Updated: )
StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/st2client | <3.4.1 | 3.4.1 |
Stackstorm Stackstorm | <3.4.1 | |
Python Python | <3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28667 is a vulnerability in StackStorm before version 3.4.1 that can cause an infinite loop and consume all available memory and disk space in certain situations.
CVE-2021-28667 affects StackStorm before version 3.4.1 when Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data from an action or rule name.
The severity of CVE-2021-28667 is rated as high with a CVSS score of 7.5.
To fix CVE-2021-28667, update StackStorm to version 3.4.1.
You can find more information about CVE-2021-28667 on the NIST NVD website, the StackStorm website, and the GitHub advisory page.