CVE-2023-2253: Red Hat Openshift API For Data Protection

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.

Affected products

  • Red Hat Openshift API For Data Protection: affected versions not specified
  • Red Hat Openshift Container Platform: version 4.0 only
  • Red Hat Openshift Developer Tools And Services: affected versions not specified

Published 2023-06-06. Last modified 2026-06-17.