Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1277

Опубликовано: 30 апр. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cloudfoundry:garden-runc:*:*:*:*:*:*:*:*
Версия до 1.13.0 (исключая)
Конфигурация 2
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
Версия до 1.28.0 (исключая)

EPSS

Процентиль: 66%
0.00515
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.

EPSS

Процентиль: 66%
0.00515
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-400