Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Vulnerability Type
不可达退出条件的循环(无限循环)
Vulnerability Title
OpenStack Swift 安全漏洞
Vulnerability Description
OpenStack Swift是OpenStack开源的一个分布式对象存储系统。 OpenStack Swift 2.36.2之前版本和2.37.2之前版本存在安全漏洞,该漏洞源于s3api中间件处理截断的aws-chunked PUT请求体时进入无限循环,StreamingInput类重复追加空缓冲区并重新读取,可能导致处理请求的代理服务器工作进程永久无响应并增加CPU和内存消耗,经身份验证的攻击者可系统性地耗尽所有代理服务器工作进程,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A