漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ReportPortal DoS vulnerability on creating a Launch with too many recursively nested elements
Vulnerability Description
ReportPortal is an AI-powered test automation platform. Prior to version 5.10.0 of the `com.epam.reportportal:service-api` module, corresponding to ReportPortal version 23.2, the ReportPortal database becomes unstable and reporting almost fully stops except for small launches with approximately 1 test inside when the test_item.path field is exceeded the allowable `ltree` field type indexing limit (path length>=120, approximately recursive nesting of the nested steps). REINDEX INDEX path_gist_idx and path_idx aren't helped. The problem was fixed in `com.epam.reportportal:service-api` module version 5.10.0 (product release 23.2), where the maximum number of nested elements were programmatically limited. A workaround is available. After deletion of the data with long paths, and reindexing both indexes (path_gist_idx and path_idx), the database becomes stable and ReportPortal works properly.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
ReportPortal 安全漏洞
Vulnerability Description
ReportPortal是ReportPortal开源的一个开源、面向服务、基于 Web 的平台。 ReportPortal 5.10.0之前版本存在安全漏洞,该漏洞源于当 test_item.path 字段超出允许的ltree字段类型索引限制时,ReportPortal 数据库会变得不稳定。
CVSS Information
N/A
Vulnerability Type
N/A