Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h62f-wm92-2cmw

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Docker Registry has Allocation of Resources Without Limits or Throttling

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

Specific Go Packages Affected

github.com/docker/distribution/registry/storage github.com/docker/distribution/registry/handlers

Пакеты

Наименование

github.com/docker/distribution

go
Затронутые версииВерсия исправления

< 2.7.0-rc.0

2.7.0-rc.0

EPSS

Процентиль: 63%
0.00442
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 5.3
redhat
больше 8 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 7.5
nvd
больше 8 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 7.5
debian
больше 8 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly ...

suse-cvrf
почти 8 лет назад

Security update for docker-distribution

EPSS

Процентиль: 63%
0.00442
Низкий

7.5 High

CVSS3

Дефекты

CWE-770