Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q3g-m353-cp4p

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of Service in Packetbeat

Packetbeat versions prior to 5.6.4 and 6.0.0 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.

Пакеты

Наименование

github.com/elastic/beats

go
Затронутые версииВерсия исправления

< 5.6.4

5.6.4

Наименование

github.com/elastic/beats

go
Затронутые версииВерсия исправления

>= 6.0.0-alpha1, < 6.0.0

6.0.0

EPSS

Процентиль: 67%
0.0054
Низкий

7.5 High

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 7.5
nvd
около 8 лет назад

Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.

EPSS

Процентиль: 67%
0.0054
Низкий

7.5 High

CVSS3

Дефекты

CWE-404