Описание
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.13.0 (исключая)
cpe:2.3:a:cloudfoundry:garden-runc:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 1.28.0 (исключая)
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00515
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.
EPSS
Процентиль: 66%
0.00515
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-400