Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16848

Опубликовано: 10 июн. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)openstack-mistralWill not fix
Red Hat OpenStack Platform 12 (Pike)openstack-mistralOut of support scope
Red Hat OpenStack Platform 13 (Queens)openstack-mistralWill not fix
Red Hat OpenStack Platform 14 (Rocky)openstack-mistralWill not fix
Red Hat OpenStack Platform 15 (Stein)openstack-mistralWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=1645332openstack-mistral: Potential Mistral Denial of Service handling recursive YAML anchor expansion

EPSS

Процентиль: 52%
0.00286
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.

CVSS3: 6.5
nvd
больше 5 лет назад

A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.

CVSS3: 6.5
debian
больше 5 лет назад

A Denial of Service (DoS) condition is possible in OpenStack Mistral i ...

CVSS3: 6.5
github
больше 3 лет назад

OpenStack Mistral DoS

EPSS

Процентиль: 52%
0.00286
Низкий

6.5 Medium

CVSS3