Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxwr-2vxm-cg7p

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Пакеты

Наименование

swift

pip
Затронутые версииВерсия исправления

< 2.3.1

2.3.1

Наименование

swift

pip
Затронутые версииВерсия исправления

>= 2.4.0, < 2.5.1

2.5.1

EPSS

Процентиль: 90%
0.05828
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

redhat
около 10 лет назад

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

CVSS3: 7.5
nvd
около 10 лет назад

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

CVSS3: 7.5
debian
около 10 лет назад

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x ...

EPSS

Процентиль: 90%
0.05828
Низкий

7.5 High

CVSS3