Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1722

Опубликовано: 27 апр. 2020
Источник: nvd
CVSS3: 5.3
CVSS2: 5.4
EPSS Низкий

Описание

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.8.0 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00368
Низкий

5.3 Medium

CVSS3

5.4 Medium

CVSS2

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.

CVSS3: 5.3
redhat
около 5 лет назад

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.

CVSS3: 5.3
debian
около 5 лет назад

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending ...

CVSS3: 5.3
github
около 3 лет назад

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.

rocky
больше 4 лет назад

Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update

EPSS

Процентиль: 58%
0.00368
Низкий

5.3 Medium

CVSS3

5.4 Medium

CVSS2

Дефекты

CWE-400
CWE-400