Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1702

Опубликовано: 27 мая 2021
Источник: nvd
CVSS3: 3.3
CVSS2: 4.3
EPSS Низкий

Описание

A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image. This flaw affects containers-image versions before 5.2.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:containers-image_project:containers-image:*:*:*:*:*:*:*:*
Версия до 5.2.0 (исключая)
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00195
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 3.5
redhat
больше 5 лет назад

A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image. This flaw affects containers-image versions before 5.2.0.

github
около 3 лет назад

A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image. This flaw affects containers-image versions before 5.2.0.

oracle-oval
почти 5 лет назад

ELSA-2020-2681: skopeo security and bug fix update (LOW)

CVSS3: 3.3
fstec
около 4 лет назад

Уязвимость пакета podman операционной системы Red Hat Enterprise Linux и корпоративной платформы Red Hat OpenShift Container Platform, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

rocky
около 5 лет назад

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

EPSS

Процентиль: 42%
0.00195
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-400