Описание
Concrete CMS vulnerable to Uncontrolled Resource Consumption leading to DoS
In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-43686
- https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes
- https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes
- https://github.com/concretecms/concretecms/releases/8.5.10
- https://github.com/concretecms/concretecms/releases/9.1.3
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31
Пакеты
Наименование
concrete5/concrete5
composer
Затронутые версииВерсия исправления
< 8.5.10
8.5.10
Наименование
concrete5/concrete5
composer
Затронутые версииВерсия исправления
>= 9.0.0, < 9.1.3
9.1.3
Связанные уязвимости
CVSS3: 6.5
nvd
около 3 лет назад
In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).