Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43744
HistoryOct 11, 2023 - 5:37 a.m.

Denial Of Service (DoS)

2023-10-1105:37:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
reportportal
vulnerability
denial of service
test_item.path
software

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

39.2%

ReportPortal is vulnerable to Denial Of Service. The vulnerability is due to exceeding the allowable ltree field type indexing limit in the test_item.path field which results in denial of service.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

39.2%