Lucene search

K
osvGoogleOSV:GHSA-PCWM-8JC3-QXVJ
HistoryJul 23, 2018 - 7:50 p.m.

Plone Denial of Service vulnerability

2018-07-2319:50:52
Google
osv.dev
14

AI Score

6.4

Confidence

High

EPSS

0.019

Percentile

88.5%

Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

AI Score

6.4

Confidence

High

EPSS

0.019

Percentile

88.5%