Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24997
HistoryApr 10, 2020 - 1:12 a.m.

Denial Of Service (DoS)

2020-04-1001:12:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.015

Percentile

86.8%

spacewalk-backend is vulnerable to denial of service. It was found that a remote attacker could upload packages to an RHN Satellite server’s NULL organization without any authorization or authentication. (The NULL organization stores packages synced from RHN Hosted.) Although an attacker cannot put packages into an arbitrary channel and have client systems download them, they could use the flaw to consume all the free space in the partition (/var/) used to store synced packages. With no free space, Satellite would be unable to download updates and new packages, preventing client systems from obtaining them.

EPSS

0.015

Percentile

86.8%

Related for VERACODE:24997