漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Vulnerability Type
不可达退出条件的循环(无限循环)
Vulnerability Title
OpenStack Swift 安全漏洞
Vulnerability Description
OpenStack Swift是OpenStack开源的一个分布式对象存储系统。 OpenStack Swift 2.36.2之前版本和2.37.2之前版本存在安全漏洞,该漏洞源于s3api中间件处理截断的aws-chunked PUT请求体时进入无限循环,StreamingInput类重复追加空缓冲区并重新读取,可能导致处理请求的代理服务器工作进程永久无响应并增加CPU和内存消耗,经身份验证的攻击者可系统性地耗尽所有代理服务器工作进程,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A