Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj4c-53qh-fp5v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.

CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.

EPSS

Процентиль: 62%
0.00421
Низкий

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.

EPSS

Процентиль: 62%
0.00421
Низкий

Дефекты

CWE-400