Описание
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
A flaw was found in python-flask. Unexpected memory usage can occur through specially crafted encoded JSON data. The highest threat from this vulnerability is to system availability. Note, this may overlap CVE-2018-1000656.
Отчет
Red Hat Satellite 6.5 ships an affected version of python-flask. However, the product is not vulnerable since the data component Crane receives from pulp_docker repository metadata with JSON uses UTF-8 encoding by default. Other supported versions of the Satellite are not affected by this vulnerability. Note: CVE-2019-1010083 is a duplicate of the flaw in CVE-2018-1000656. However, the 2019 flaw identifies newer affected products.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 2 | python-flask | Out of support scope | ||
| Red Hat Ceph Storage 3 | python-flask | Affected | ||
| Red Hat Ceph Storage 7 | python-flask | Affected | ||
| Red Hat Enterprise Linux 7 | python-flask | Not affected | ||
| Red Hat Enterprise Linux 8 | python-flask | Not affected | ||
| Red Hat OpenShift Container Platform 4 | python-flask | Not affected | ||
| Red Hat OpenStack Platform 16 (Train) | python-flask | Not affected | ||
| Red Hat Quay 3 | python-flask | Not affected | ||
| Red Hat Satellite 6 | python-flask | Will not fix | ||
| Red Hat Storage 3 | python-flask | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
The Pallets Project Flask before 1.0 is affected by: unexpected memory ...
Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usage
7.5 High
CVSS3