Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11409
HistoryJan 15, 2019 - 9:01 a.m.

Denial Of Service (DoS) Via CPU Consumption

2019-01-1509:01:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.053 Low

EPSS

Percentile

93.1%

Red Hat Storage is vulnerable to a denial of service attack. The attack is due to the flaw in the way Python’s SSL module implementation performed matching of certain certificate names, allowing the attacker to input a valid certificate containing multiple wildcard characters resulting in excessive consumption of CPU in validation stage.

References