Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3x5-r85c-grp5

Опубликовано: 02 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.

In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.

EPSS

Процентиль: 66%
0.00522
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.

EPSS

Процентиль: 66%
0.00522
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-674