← voltar
CVE-2020-5423

Cloud Controller is vulnerable to denial of service via YAML parsing

CVSS 7.5 HIGHEPSS 1.1%CWE-400
CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →