Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4ppj-4p4v-jf4p

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

< 8.0.0a0

8.0.0a0

EPSS

Процентиль: 87%
0.03139
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119
CWE-1284

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 13 лет назад

A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.

CVSS3: 6.5
redhat
больше 13 лет назад

A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.

CVSS3: 6.5
nvd
больше 13 лет назад

A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.

CVSS3: 6.5
debian
больше 13 лет назад

A flaw was found in OpenStack Keystone. A remote attacker could exploi ...

EPSS

Процентиль: 87%
0.03139
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119
CWE-1284