CVE-2021-28667

HIGH

Stackstorm < 3.4.1 - Infinite Loop

Title source: rule
STIX 2.1

Description

StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name).

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0067
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (2)
pypi/st2client 0 - 3.4.1PyPI
stackstorm/stackstorm < 3.4.1
Published Mar 18, 2021
Tracked Since Feb 18, 2026