Safety vulnerability ID: 40034
The information on this page was manually curated by our Cybersecurity Intelligence Team.
StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name). See CVE-2021-28667.
Latest version: 3.8.1
Python client library and CLI for the StackStorm (st2) event-driven automation platform.
StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name). See CVE-2021-28667.
MISC:https://stackstorm.com/2021/03/10/stackstorm-v3-4-1-security-fix/: https://stackstorm.com/2021/03/10/stackstorm-v3-4-1-security-fix/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application