Описание
A flaw was found in the /v2/_catalog endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: n). This vulnerability allows a malicious user to submit an unreasonably large value for n, causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | helm | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Will not fix | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-openshift-apiserver-rhel9 | Affected | ||
| OADP-1.1-RHEL-8 | oadp/oadp-velero-plugin-rhel8 | Fixed | RHSA-2023:5314 | 20.09.2023 |
| Red Hat OpenShift Container Platform 4.11 | openshift4/ose-docker-registry | Fixed | RHSA-2023:5697 | 18.10.2023 |
| Red Hat OpenShift Container Platform 4.12 | openshift4/ose-docker-registry | Fixed | RHSA-2023:5390 | 04.10.2023 |
| Red Hat OpenShift Container Platform 4.13 | openshift4/ose-docker-registry | Fixed | RHSA-2023:5155 | 19.09.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
A flaw was found in the `/v2/_catalog` endpoint in distribution/distri ...
EPSS
6.5 Medium
CVSS3