PT-2017-6112 · Red Hat · Red Hat Cloudforms
Published
2017-10-18
·
Updated
2017-11-07
·
CVE-2014-7813
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Red Hat CloudForms version 3
Description:
The issue allows remote authenticated users to cause a denial of service, specifically resource consumption, through vectors involving calls to the
to sym rails function and a lack of garbage collection of inserted symbols.Recommendations:
For Red Hat CloudForms version 3, consider restricting access to the
to sym rails function as a temporary workaround until a patch is available. Additionally, implementing proper garbage collection of inserted symbols may help mitigate the risk of resource consumption.Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Cloudforms