Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service
Vulnerability Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
Elastic Fleet Server 资源管理错误漏洞
Vulnerability Description
Elastic Fleet Server是荷兰Elastic公司开源的一个设备集中管理服务。 Elastic Fleet Server 9.0.0至9.2.4版本和8.0.0至8.19.10版本存在资源管理错误漏洞,该漏洞源于资源无限制分配或节流问题,可能导致攻击者向上传端点提交特制请求,造成大量内存消耗,从而使得Fleet Server无法使用。
CVSS Information
N/A
Vulnerability Type
N/A