CVE Vulnerabilities

CVE-2020-6855

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Feb 06, 2020 | Modified: Feb 07, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and results in a denial of service.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Jobscheduler Sos-berlin 1.11 (including) 1.11 (including)
Jobscheduler Sos-berlin 1.13.2 (including) 1.13.2 (including)

References