Описание
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- Patch
- PatchVendor Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 23.0.4 (включая) до 29.0.6 (исключая)Версия от 30.0.0 (включая) до 32.0.2 (исключая)Версия от 33.0.0 (включая) до 35.0.2 (исключая)
Одно из
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00466
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-696
Связанные уязвимости
CVSS3: 4.3
ubuntu
3 месяца назад
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
CVSS3: 4.3
debian
3 месяца назад
In OpenStack Ironic through 35.x before a3f6d73, during image handling ...
CVSS3: 4.3
github
3 месяца назад
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
EPSS
Процентиль: 38%
0.00466
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-696