Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-1580: DEVO-2023-0007

Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.

CVE
#vulnerability#dos

Security & Compliance Reporting a Security Issue Advisories

Affected Products

Devolutions Gateway 2023.1.1 and earlier.

Change Log

Initial publication - 2023-03-22

Product

Devolutions Gateway

Summary

Devolutions Gateway is affected by a vulnerability.

Uncontrolled resource consumption in the logging feature of Devolutions Gateway

Description

Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk with specially crafted requests and render the system unusable.

Remediation and Workarounds

Upgrade to Devolutions Gateway 2023.1.2 and higher.

Severity

Medium - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Affected Products

Devolutions Gateway 2023.1.1 and earlier.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda