CVE-2023-2253: Red Hat Openshift API For Data Protection
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
Affected products
- Red Hat Openshift API For Data Protection: affected versions not specified
- Red Hat Openshift Container Platform: version 4.0 only
- Red Hat Openshift Developer Tools And Services: affected versions not specified
Published 2023-06-06. Last modified 2026-06-17.