Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h62f-wm92-2cmw

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Docker Registry has Allocation of Resources Without Limits or Throttling

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

Specific Go Packages Affected

github.com/docker/distribution/registry/storage github.com/docker/distribution/registry/handlers

Пакеты

Наименование

github.com/docker/distribution

go
Затронутые версииВерсия исправления

< 2.7.0-rc.0

2.7.0-rc.0

EPSS

Процентиль: 87%
0.03192
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 5.3
redhat
около 9 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 7.5
nvd
около 9 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 7.5
debian
около 9 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly ...

suse-cvrf
больше 8 лет назад

Security update for docker-distribution

EPSS

Процентиль: 87%
0.03192
Низкий

7.5 High

CVSS3

Дефекты

CWE-770