F5-K000141024: Medium severity f5 big-ip next central manager vulnerability
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000141024?
The severity of F5-K000141024 is considered high due to the potential for an infinite loop.
How do I fix F5-K000141024?
To fix F5-K000141024, users should update to the fixed versions of the affected F5 products as specified in the advisory.
Which products are affected by F5-K000141024?
F5-K000141024 affects several products including BIG-IP Next Central Manager, BIG-IP Next SPK, BIG-IP Next CNF, F5OS-A, and F5OS-C within specific version ranges.
What is the impact of F5-K000141024?
The impact of F5-K000141024 is that it can cause applications to become unresponsive due to an infinite loop during the JSON unmarshaling process.
Is there a workaround for F5-K000141024?
Currently, there are no known workarounds for F5-K000141024; updating to the patched versions is recommended.