Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5295

Опубликовано: 20 янв. 2016
Источник: nvd
CVSS3: 5.4
CVSS2: 5.5
EPSS Низкий

Описание

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:orchestration_api:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.1 (исключая)
cpe:2.3:a:openstack:orchestration_api:*:*:*:*:*:*:*:*
Версия от 2015.1.0 (включая) до 2015.1.3 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openstack:7.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01636
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 10 лет назад

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

redhat
около 10 лет назад

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

CVSS3: 5.4
debian
около 10 лет назад

The template-validate command in OpenStack Orchestration API (Heat) be ...

CVSS3: 5.4
github
больше 3 лет назад

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

EPSS

Процентиль: 81%
0.01636
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-119