Safety vulnerability ID: 40034
The information on this page was manually curated by our Cybersecurity Intelligence Team.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 3.9.0
Python client library and CLI for the StackStorm (st2) event-driven automation platform.
[This affected versions has been limited. Please create a free account to view the full affected versions.]
[This fixed versions has been limited. Please create a free account to view the full fixed versions.]
StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name). See CVE-2021-28667.
MISC:https://stackstorm.com/2021/03/10/stackstorm-v3-4-1-security-fix/: https://stackstorm.com/2021/03/10/stackstorm-v3-4-1-security-fix/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application