Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gcv-g5q9-f633

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

It has been discovered that redhat-certification does not properly limit the number of recursive definitions of entities in XML documents while parsing the status of a host. A remote attacker could use this vulnerability to consume all the memory of the server and cause a Denial of Service. This flaw affects redhat-certification version 7.

It has been discovered that redhat-certification does not properly limit the number of recursive definitions of entities in XML documents while parsing the status of a host. A remote attacker could use this vulnerability to consume all the memory of the server and cause a Denial of Service. This flaw affects redhat-certification version 7.

EPSS

Процентиль: 78%
0.0117
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-776

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.

CVSS3: 7.5
nvd
больше 4 лет назад

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.

EPSS

Процентиль: 78%
0.0117
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-776