The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient input validation of requests by an unauthenticated remote user might lead to a partial DoS of the service. Only the request of the attacker is affected by this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2023-03-27T13:41:13.756Z
Updated: 2024-08-03T15:02:36.563Z
Reserved: 2022-12-22T04:58:40.028Z
Link: CVE-2022-47925
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-27T14:15:07.767
Modified: 2024-02-15T11:15:08.203
Link: CVE-2022-47925
Redhat
No data.