Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32623

Опубликовано: 16 июн. 2021
Источник: nvd
CVSS3: 8.1
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to 9.6 are vulnerable to the billion laughs attack, which allows an attacker to easily execute a (seemingly permanent) denial of service attack, essentially taking down Opencast using a single HTTP request. To exploit this, users need to have ingest privileges, limiting the group of potential attackers The problem has been fixed in Opencast 9.6. There is no known workaround for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apereo:opencast:*:*:*:*:*:*:*:*
Версия до 9.6 (исключая)

EPSS

Процентиль: 54%
0.00308
Низкий

8.1 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-776

Связанные уязвимости

CVSS3: 8.1
github
больше 4 лет назад

Billion laughs attack (XML bomb)

EPSS

Процентиль: 54%
0.00308
Низкий

8.1 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-776