CVE Vulnerabilities

CVE-2024-28863

Uncontrolled Resource Consumption

Published: Mar 21, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

Name Vendor Start Version End Version
Red Hat Developer Hub 1.2 on RHEL 9 RedHat rhdh/rhdh-hub-rhel9:1.2-132 *
Red Hat Enterprise Linux 8 RedHat nodejs:20-8100020240808073736.489197e6 *
Red Hat Enterprise Linux 8 RedHat nodejs:18-8100020240807161023.489197e6 *
Red Hat Enterprise Linux 9 RedHat nodejs:18-9040020240807131341.rhel9 *
Red Hat Migration Toolkit for Containers 1.8 RedHat rhmtc/openshift-migration-ui-rhel8:v1.8.4-10 *
Red Hat Satellite 6 RedHat ansible-collection-redhat-satellite *
Red Hat Satellite 6 RedHat ansible-collection-redhat-satellite_operations *
Red Hat Satellite 6 RedHat ansible-lint *
Red Hat Satellite 6 RedHat ansiblerole-foreman_scap_client *
Red Hat Satellite 6 RedHat ansiblerole-insights-client *
Red Hat Satellite 6 RedHat ansible-runner *
Red Hat Satellite 6 RedHat candlepin *
Red Hat Satellite 6 RedHat cjson *
Red Hat Satellite 6 RedHat createrepo_c *
Red Hat Satellite 6 RedHat dynflow-utils *
Red Hat Satellite 6 RedHat foreman *
Red Hat Satellite 6 RedHat foreman-bootloaders-redhat *
Red Hat Satellite 6 RedHat foreman-discovery-image *
Red Hat Satellite 6 RedHat foreman-discovery-image-service *
Red Hat Satellite 6 RedHat foreman-fapolicyd *
Red Hat Satellite 6 RedHat foreman-installer *
Red Hat Satellite 6 RedHat foreman-obsolete-packages *
Red Hat Satellite 6 RedHat foreman-proxy *
Red Hat Satellite 6 RedHat foreman-selinux *
Red Hat Satellite 6 RedHat katello *
Red Hat Satellite 6 RedHat katello-certs-tools *
Red Hat Satellite 6 RedHat katello-client-bootstrap *
Red Hat Satellite 6 RedHat katello-selinux *
Red Hat Satellite 6 RedHat libcomps *
Red Hat Satellite 6 RedHat libsodium *
Red Hat Satellite 6 RedHat libsolv *
Red Hat Satellite 6 RedHat mosquitto *
Red Hat Satellite 6 RedHat postgresql-evr *
Red Hat Satellite 6 RedHat pulpcore-obsolete-packages *
Red Hat Satellite 6 RedHat pulpcore-selinux *
Red Hat Satellite 6 RedHat puppet-agent *
Red Hat Satellite 6 RedHat puppet-agent-oauth *
Red Hat Satellite 6 RedHat puppet-foreman_scap_client *
Red Hat Satellite 6 RedHat puppetlabs-stdlib *
Red Hat Satellite 6 RedHat puppetserver *
Red Hat Satellite 6 RedHat python3.11-packaging *
Red Hat Satellite 6 RedHat python-aiodns *
Red Hat Satellite 6 RedHat python-aiofiles *
Red Hat Satellite 6 RedHat python-aiohttp *
Red Hat Satellite 6 RedHat python-aiohttp-xmlrpc *
Red Hat Satellite 6 RedHat python-aioredis *
Red Hat Satellite 6 RedHat python-aiosignal *
Red Hat Satellite 6 RedHat python-ansible-builder *
Red Hat Satellite 6 RedHat python-asgiref *
Red Hat Satellite 6 RedHat python-asyncio-throttle *
Red Hat Satellite 6 RedHat python-async-lru *
Red Hat Satellite 6 RedHat python-async-timeout *
Red Hat Satellite 6 RedHat python-attrs *
Red Hat Satellite 6 RedHat python-backoff *
Red Hat Satellite 6 RedHat python-bindep *
Red Hat Satellite 6 RedHat python-bleach *
Red Hat Satellite 6 RedHat python-bleach-allowlist *
Red Hat Satellite 6 RedHat python-bracex *
Red Hat Satellite 6 RedHat python-brotli *
Red Hat Satellite 6 RedHat python-certifi *
Red Hat Satellite 6 RedHat python-cffi *
Red Hat Satellite 6 RedHat python-chardet *
Red Hat Satellite 6 RedHat python-charset-normalizer *
Red Hat Satellite 6 RedHat python-click *
Red Hat Satellite 6 RedHat python-click-shell *
Red Hat Satellite 6 RedHat python-colorama *
Red Hat Satellite 6 RedHat python-commonmark *
Red Hat Satellite 6 RedHat python-contextlib2 *
Red Hat Satellite 6 RedHat python-cryptography *
Red Hat Satellite 6 RedHat python-daemon *
Red Hat Satellite 6 RedHat python-dataclasses *
Red Hat Satellite 6 RedHat python-dateutil *
Red Hat Satellite 6 RedHat python-debian *
Red Hat Satellite 6 RedHat python-defusedxml *
Red Hat Satellite 6 RedHat python-deprecated *
Red Hat Satellite 6 RedHat python-diff-match-patch *
Red Hat Satellite 6 RedHat python-distro *
Red Hat Satellite 6 RedHat python-django *
Red Hat Satellite 6 RedHat python-django-filter *
Red Hat Satellite 6 RedHat python-django-guid *
Red Hat Satellite 6 RedHat python-django-import-export *
Red Hat Satellite 6 RedHat python-django-lifecycle *
Red Hat Satellite 6 RedHat python-django-readonly-field *
Red Hat Satellite 6 RedHat python-djangorestframework *
Red Hat Satellite 6 RedHat python-djangorestframework-queryfields *
Red Hat Satellite 6 RedHat python-docutils *
Red Hat Satellite 6 RedHat python-drf-access-policy *
Red Hat Satellite 6 RedHat python-drf-nested-routers *
Red Hat Satellite 6 RedHat python-drf-spectacular *
Red Hat Satellite 6 RedHat python-dynaconf *
Red Hat Satellite 6 RedHat python-ecdsa *
Red Hat Satellite 6 RedHat python-enrich *
Red Hat Satellite 6 RedHat python-et-xmlfile *
Red Hat Satellite 6 RedHat python-flake8 *
Red Hat Satellite 6 RedHat python-frozenlist *
Red Hat Satellite 6 RedHat python-future *
Red Hat Satellite 6 RedHat python-galaxy-importer *
Red Hat Satellite 6 RedHat python-gitdb *
Red Hat Satellite 6 RedHat python-gitpython *
Red Hat Satellite 6 RedHat python-gnupg *
Red Hat Satellite 6 RedHat python-googleapis-common-protos *
Red Hat Satellite 6 RedHat python-grpcio *
Red Hat Satellite 6 RedHat python-gunicorn *
Red Hat Satellite 6 RedHat python-importlib-metadata *
Red Hat Satellite 6 RedHat python-inflection *
Red Hat Satellite 6 RedHat python-iniparse *
Red Hat Satellite 6 RedHat python-jinja2 *
Red Hat Satellite 6 RedHat python-jq *
Red Hat Satellite 6 RedHat python-jsonschema *
Red Hat Satellite 6 RedHat python-json-stream *
Red Hat Satellite 6 RedHat python-json-stream-rs-tokenizer *
Red Hat Satellite 6 RedHat python-lockfile *
Red Hat Satellite 6 RedHat python-lxml *
Red Hat Satellite 6 RedHat python-markdown *
Red Hat Satellite 6 RedHat python-markuppy *
Red Hat Satellite 6 RedHat python-markupsafe *
Red Hat Satellite 6 RedHat python-mccabe *
Red Hat Satellite 6 RedHat python-multidict *
Red Hat Satellite 6 RedHat python-odfpy *
Red Hat Satellite 6 RedHat python-openpyxl *
Red Hat Satellite 6 RedHat python-opentelemetry_api *
Red Hat Satellite 6 RedHat python-opentelemetry_distro *
Red Hat Satellite 6 RedHat python-opentelemetry_exporter_otlp *
Red Hat Satellite 6 RedHat python-opentelemetry_exporter_otlp_proto_common *
Red Hat Satellite 6 RedHat python-opentelemetry_exporter_otlp_proto_grpc *
Red Hat Satellite 6 RedHat python-opentelemetry_exporter_otlp_proto_http *
Red Hat Satellite 6 RedHat python-opentelemetry_instrumentation *
Red Hat Satellite 6 RedHat python-opentelemetry_instrumentation_django *
Red Hat Satellite 6 RedHat python-opentelemetry_instrumentation_wsgi *
Red Hat Satellite 6 RedHat python-opentelemetry_proto *
Red Hat Satellite 6 RedHat python-opentelemetry_sdk *
Red Hat Satellite 6 RedHat python-opentelemetry_semantic_conventions *
Red Hat Satellite 6 RedHat python-opentelemetry_util_http *
Red Hat Satellite 6 RedHat python-packaging *
Red Hat Satellite 6 RedHat python-parsley *
Red Hat Satellite 6 RedHat python-pbr *
Red Hat Satellite 6 RedHat python-pexpect *
Red Hat Satellite 6 RedHat python-pillow *
Red Hat Satellite 6 RedHat python-productmd *
Red Hat Satellite 6 RedHat python-protobuf *
Red Hat Satellite 6 RedHat python-psycopg *
Red Hat Satellite 6 RedHat python-ptyprocess *
Red Hat Satellite 6 RedHat python-pulp-ansible *
Red Hat Satellite 6 RedHat python-pulp-certguard *
Red Hat Satellite 6 RedHat python-pulp-cli *
Red Hat Satellite 6 RedHat python-pulp-container *
Red Hat Satellite 6 RedHat python-pulpcore *
Red Hat Satellite 6 RedHat python-pulp-deb *
Red Hat Satellite 6 RedHat python-pulp-file *
Red Hat Satellite 6 RedHat python-pulp-glue *
Red Hat Satellite 6 RedHat python-pulp_manifest *
Red Hat Satellite 6 RedHat python-pulp-rpm *
Red Hat Satellite 6 RedHat python-pycares *
Red Hat Satellite 6 RedHat python-pycodestyle *
Red Hat Satellite 6 RedHat python-pycparser *
Red Hat Satellite 6 RedHat python-pycryptodomex *
Red Hat Satellite 6 RedHat python-pyflakes *
Red Hat Satellite 6 RedHat python-pygments *
Red Hat Satellite 6 RedHat python-pygtrie *
Red Hat Satellite 6 RedHat python-pyjwkest *
Red Hat Satellite 6 RedHat python-pyjwt *
Red Hat Satellite 6 RedHat python-pyOpenSSL *
Red Hat Satellite 6 RedHat python-pyparsing *
Red Hat Satellite 6 RedHat python-pyrsistent *
Red Hat Satellite 6 RedHat python-pytz *
Red Hat Satellite 6 RedHat python-redis *
Red Hat Satellite 6 RedHat python-requests *
Red Hat Satellite 6 RedHat python-requirements-parser *
Red Hat Satellite 6 RedHat python-rhsm *
Red Hat Satellite 6 RedHat python-rich *
Red Hat Satellite 6 RedHat python-ruamel-yaml *
Red Hat Satellite 6 RedHat python-ruamel-yaml-clib *
Red Hat Satellite 6 RedHat python-schema *
Red Hat Satellite 6 RedHat python-semantic-version *
Red Hat Satellite 6 RedHat python-six *
Red Hat Satellite 6 RedHat python-smmap *
Red Hat Satellite 6 RedHat python-solv *
Red Hat Satellite 6 RedHat python-sqlparse *
Red Hat Satellite 6 RedHat python-tablib *
Red Hat Satellite 6 RedHat python-tenacity *
Red Hat Satellite 6 RedHat python-toml *
Red Hat Satellite 6 RedHat python-types-cryptography *
Red Hat Satellite 6 RedHat python-typing-extensions *
Red Hat Satellite 6 RedHat python-uritemplate *
Red Hat Satellite 6 RedHat python-urllib3 *
Red Hat Satellite 6 RedHat python-urlman *
Red Hat Satellite 6 RedHat python-url-normalize *
Red Hat Satellite 6 RedHat python-uuid6 *
Red Hat Satellite 6 RedHat python-wcmatch *
Red Hat Satellite 6 RedHat python-webencodings *
Red Hat Satellite 6 RedHat python-websockify *
Red Hat Satellite 6 RedHat python-whitenoise *
Red Hat Satellite 6 RedHat python-wrapt *
Red Hat Satellite 6 RedHat python-xlrd *
Red Hat Satellite 6 RedHat python-xlwt *
Red Hat Satellite 6 RedHat python-yarl *
Red Hat Satellite 6 RedHat python-zipp *
Red Hat Satellite 6 RedHat rubygem-actioncable *
Red Hat Satellite 6 RedHat rubygem-actionmailbox *
Red Hat Satellite 6 RedHat rubygem-actionmailer *
Red Hat Satellite 6 RedHat rubygem-actionpack *
Red Hat Satellite 6 RedHat rubygem-actiontext *
Red Hat Satellite 6 RedHat rubygem-actionview *
Red Hat Satellite 6 RedHat rubygem-activejob *
Red Hat Satellite 6 RedHat rubygem-activemodel *
Red Hat Satellite 6 RedHat rubygem-activerecord *
Red Hat Satellite 6 RedHat rubygem-activerecord-import *
Red Hat Satellite 6 RedHat rubygem-activerecord-session_store *
Red Hat Satellite 6 RedHat rubygem-activestorage *
Red Hat Satellite 6 RedHat rubygem-activesupport *
Red Hat Satellite 6 RedHat rubygem-acts_as_list *
Red Hat Satellite 6 RedHat rubygem-addressable *
Red Hat Satellite 6 RedHat rubygem-algebrick *
Red Hat Satellite 6 RedHat rubygem-amazing_print *
Red Hat Satellite 6 RedHat rubygem-ancestry *
Red Hat Satellite 6 RedHat rubygem-angular-rails-templates *
Red Hat Satellite 6 RedHat rubygem-ansi *
Red Hat Satellite 6 RedHat rubygem-apipie-bindings *
Red Hat Satellite 6 RedHat rubygem-apipie-dsl *
Red Hat Satellite 6 RedHat rubygem-apipie-params *
Red Hat Satellite 6 RedHat rubygem-apipie-rails *
Red Hat Satellite 6 RedHat rubygem-audited *
Red Hat Satellite 6 RedHat rubygem-azure_mgmt_compute *
Red Hat Satellite 6 RedHat rubygem-azure_mgmt_network *
Red Hat Satellite 6 RedHat rubygem-azure_mgmt_resources *
Red Hat Satellite 6 RedHat rubygem-azure_mgmt_storage *
Red Hat Satellite 6 RedHat rubygem-azure_mgmt_subscriptions *
Red Hat Satellite 6 RedHat rubygem-bcrypt *
Red Hat Satellite 6 RedHat rubygem-builder *
Red Hat Satellite 6 RedHat rubygem-bundler_ext *
Red Hat Satellite 6 RedHat rubygem-clamp *
Red Hat Satellite 6 RedHat rubygem-coffee-rails *
Red Hat Satellite 6 RedHat rubygem-coffee-script *
Red Hat Satellite 6 RedHat rubygem-coffee-script-source *
Red Hat Satellite 6 RedHat rubygem-colorize *
Red Hat Satellite 6 RedHat rubygem-concurrent-ruby *
Red Hat Satellite 6 RedHat rubygem-concurrent-ruby-edge *
Red Hat Satellite 6 RedHat rubygem-connection_pool *
Red Hat Satellite 6 RedHat rubygem-crass *
Red Hat Satellite 6 RedHat rubygem-css_parser *
Red Hat Satellite 6 RedHat rubygem-daemons *
Red Hat Satellite 6 RedHat rubygem-deacon *
Red Hat Satellite 6 RedHat rubygem-declarative *
Red Hat Satellite 6 RedHat rubygem-deep_cloneable *
Red Hat Satellite 6 RedHat rubygem-deface *
Red Hat Satellite 6 RedHat rubygem-diffy *
Red Hat Satellite 6 RedHat rubygem-domain_name *
Red Hat Satellite 6 RedHat rubygem-dynflow *
Red Hat Satellite 6 RedHat rubygem-erubi *
Red Hat Satellite 6 RedHat rubygem-et-orbi *
Red Hat Satellite 6 RedHat rubygem-excon *
Red Hat Satellite 6 RedHat rubygem-execjs *
Red Hat Satellite 6 RedHat rubygem-facter *
Red Hat Satellite 6 RedHat rubygem-faraday *
Red Hat Satellite 6 RedHat rubygem-faraday-cookie_jar *
Red Hat Satellite 6 RedHat rubygem-faraday-em_http *
Red Hat Satellite 6 RedHat rubygem-faraday-em_synchrony *
Red Hat Satellite 6 RedHat rubygem-faraday-excon *
Red Hat Satellite 6 RedHat rubygem-faraday-httpclient *
Red Hat Satellite 6 RedHat rubygem-faraday_middleware *
Red Hat Satellite 6 RedHat rubygem-faraday-multipart *
Red Hat Satellite 6 RedHat rubygem-faraday-net_http *
Red Hat Satellite 6 RedHat rubygem-faraday-net_http_persistent *
Red Hat Satellite 6 RedHat rubygem-faraday-patron *
Red Hat Satellite 6 RedHat rubygem-faraday-rack *
Red Hat Satellite 6 RedHat rubygem-faraday-retry *
Red Hat Satellite 6 RedHat rubygem-fast_gettext *
Red Hat Satellite 6 RedHat rubygem-ffi *
Red Hat Satellite 6 RedHat rubygem-fog-aws *
Red Hat Satellite 6 RedHat rubygem-fog-core *
Red Hat Satellite 6 RedHat rubygem-fog-json *
Red Hat Satellite 6 RedHat rubygem-fog-kubevirt *
Red Hat Satellite 6 RedHat rubygem-fog-libvirt *
Red Hat Satellite 6 RedHat rubygem-fog-openstack *
Red Hat Satellite 6 RedHat rubygem-fog-ovirt *
Red Hat Satellite 6 RedHat rubygem-fog-vsphere *
Red Hat Satellite 6 RedHat rubygem-fog-xml *
Red Hat Satellite 6 RedHat rubygem-foreman_ansible *
Red Hat Satellite 6 RedHat rubygem-foreman_azure_rm *
Red Hat Satellite 6 RedHat rubygem-foreman_bootdisk *
Red Hat Satellite 6 RedHat rubygem-foreman_discovery *
Red Hat Satellite 6 RedHat rubygem-foreman_google *
Red Hat Satellite 6 RedHat rubygem-foreman_kubevirt *
Red Hat Satellite 6 RedHat rubygem-foreman_leapp *
Red Hat Satellite 6 RedHat rubygem-foreman_maintain *
Red Hat Satellite 6 RedHat rubygem-foreman_openscap *
Red Hat Satellite 6 RedHat rubygem-foreman_puppet *
Red Hat Satellite 6 RedHat rubygem-foreman_remote_execution *
Red Hat Satellite 6 RedHat rubygem-foreman_rh_cloud *
Red Hat Satellite 6 RedHat rubygem-foreman_scap_client *
Red Hat Satellite 6 RedHat rubygem-foreman-tasks *
Red Hat Satellite 6 RedHat rubygem-foreman_templates *
Red Hat Satellite 6 RedHat rubygem-foreman_theme_satellite *
Red Hat Satellite 6 RedHat rubygem-foreman_virt_who_configure *
Red Hat Satellite 6 RedHat rubygem-foreman_webhooks *
Red Hat Satellite 6 RedHat rubygem-formatador *
Red Hat Satellite 6 RedHat rubygem-friendly_id *
Red Hat Satellite 6 RedHat rubygem-fugit *
Red Hat Satellite 6 RedHat rubygem-fx *
Red Hat Satellite 6 RedHat rubygem-gapic-common *
Red Hat Satellite 6 RedHat rubygem-get_process_mem *
Red Hat Satellite 6 RedHat rubygem-gettext_i18n_rails *
Red Hat Satellite 6 RedHat rubygem-git *
Red Hat Satellite 6 RedHat rubygem-gitlab-sidekiq-fetcher *
Red Hat Satellite 6 RedHat rubygem-globalid *
Red Hat Satellite 6 RedHat rubygem-googleapis-common-protos *
Red Hat Satellite 6 RedHat rubygem-googleapis-common-protos-types *
Red Hat Satellite 6 RedHat rubygem-google-apis-compute_v1 *
Red Hat Satellite 6 RedHat rubygem-google-apis-core *
Red Hat Satellite 6 RedHat rubygem-googleauth *
Red Hat Satellite 6 RedHat rubygem-google-cloud-common *
Red Hat Satellite 6 RedHat rubygem-google-cloud-compute *
Red Hat Satellite 6 RedHat rubygem-google-cloud-compute-v1 *
Red Hat Satellite 6 RedHat rubygem-google-cloud-core *
Red Hat Satellite 6 RedHat rubygem-google-cloud-env *
Red Hat Satellite 6 RedHat rubygem-google-cloud-errors *
Red Hat Satellite 6 RedHat rubygem-google-protobuf *
Red Hat Satellite 6 RedHat rubygem-graphql *
Red Hat Satellite 6 RedHat rubygem-graphql-batch *
Red Hat Satellite 6 RedHat rubygem-grpc *
Red Hat Satellite 6 RedHat rubygem-gssapi *
Red Hat Satellite 6 RedHat rubygem-hammer_cli *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_admin *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_ansible *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_azure_rm *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_bootdisk *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_discovery *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_google *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_kubevirt *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_leapp *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_openscap *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_puppet *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_remote_execution *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_tasks *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_templates *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_virt_who_configure *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_foreman_webhooks *
Red Hat Satellite 6 RedHat rubygem-hammer_cli_katello *
Red Hat Satellite 6 RedHat rubygem-hashie *
Red Hat Satellite 6 RedHat rubygem-highline *
Red Hat Satellite 6 RedHat rubygem-hocon *
Red Hat Satellite 6 RedHat rubygem-http *
Red Hat Satellite 6 RedHat rubygem-http-accept *
Red Hat Satellite 6 RedHat rubygem-httpclient *
Red Hat Satellite 6 RedHat rubygem-http-cookie *
Red Hat Satellite 6 RedHat rubygem-http-form_data *
Red Hat Satellite 6 RedHat rubygem-http_parser.rb *
Red Hat Satellite 6 RedHat rubygem-i18n *
Red Hat Satellite 6 RedHat rubygem-infoblox *
Red Hat Satellite 6 RedHat rubygem-jgrep *
Red Hat Satellite 6 RedHat rubygem-journald-logger *
Red Hat Satellite 6 RedHat rubygem-journald-native *
Red Hat Satellite 6 RedHat rubygem-jsonpath *
Red Hat Satellite 6 RedHat rubygem-jwt *
Red Hat Satellite 6 RedHat rubygem-kafo *
Red Hat Satellite 6 RedHat rubygem-kafo_parsers *
Red Hat Satellite 6 RedHat rubygem-kafo_wizards *
Red Hat Satellite 6 RedHat rubygem-katello *
Red Hat Satellite 6 RedHat rubygem-kubeclient *
Red Hat Satellite 6 RedHat rubygem-ldap_fluff *
Red Hat Satellite 6 RedHat rubygem-little-plugger *
Red Hat Satellite 6 RedHat rubygem-locale *
Red Hat Satellite 6 RedHat rubygem-logging *
Red Hat Satellite 6 RedHat rubygem-logging-journald *
Red Hat Satellite 6 RedHat rubygem-loofah *
Red Hat Satellite 6 RedHat rubygem-mail *
Red Hat Satellite 6 RedHat rubygem-marcel *
Red Hat Satellite 6 RedHat rubygem-memoist *
Red Hat Satellite 6 RedHat rubygem-method_source *
Red Hat Satellite 6 RedHat rubygem-mime-types *
Red Hat Satellite 6 RedHat rubygem-mime-types-data *
Red Hat Satellite 6 RedHat rubygem-mini_mime *
Red Hat Satellite 6 RedHat rubygem-mqtt *
Red Hat Satellite 6 RedHat rubygem-msgpack *
Red Hat Satellite 6 RedHat rubygem-ms_rest *
Red Hat Satellite 6 RedHat rubygem-ms_rest_azure *
Red Hat Satellite 6 RedHat rubygem-multi_json *
Red Hat Satellite 6 RedHat rubygem-multipart-post *
Red Hat Satellite 6 RedHat rubygem-mustermann *
Red Hat Satellite 6 RedHat rubygem-net_http_unix *
Red Hat Satellite 6 RedHat rubygem-net-ldap *
Red Hat Satellite 6 RedHat rubygem-net-ping *
Red Hat Satellite 6 RedHat rubygem-netrc *
Red Hat Satellite 6 RedHat rubygem-net-scp *
Red Hat Satellite 6 RedHat rubygem-net-ssh *
Red Hat Satellite 6 RedHat rubygem-net-ssh-krb *
Red Hat Satellite 6 RedHat rubygem-newt *
Red Hat Satellite 6 RedHat rubygem-nio4r *
Red Hat Satellite 6 RedHat rubygem-nokogiri *
Red Hat Satellite 6 RedHat rubygem-oauth *
Red Hat Satellite 6 RedHat rubygem-oauth-tty *
Red Hat Satellite 6 RedHat rubygem-openscap *
Red Hat Satellite 6 RedHat rubygem-openscap_parser *
Red Hat Satellite 6 RedHat rubygem-optimist *
Red Hat Satellite 6 RedHat rubygem-os *
Red Hat Satellite 6 RedHat rubygem-ovirt-engine-sdk *
Red Hat Satellite 6 RedHat rubygem-ovirt_provision_plugin *
Red Hat Satellite 6 RedHat rubygem-parallel *
Red Hat Satellite 6 RedHat rubygem-pg *
Red Hat Satellite 6 RedHat rubygem-polyglot *
Red Hat Satellite 6 RedHat rubygem-powerbar *
Red Hat Satellite 6 RedHat rubygem-prometheus-client *
Red Hat Satellite 6 RedHat rubygem-promise.rb *
Red Hat Satellite 6 RedHat rubygem-public_suffix *
Red Hat Satellite 6 RedHat rubygem-pulp_ansible_client *
Red Hat Satellite 6 RedHat rubygem-pulp_certguard_client *
Red Hat Satellite 6 RedHat rubygem-pulp_container_client *
Red Hat Satellite 6 RedHat rubygem-pulpcore_client *
Red Hat Satellite 6 RedHat rubygem-pulp_deb_client *
Red Hat Satellite 6 RedHat rubygem-pulp_file_client *
Red Hat Satellite 6 RedHat rubygem-pulp_ostree_client *
Red Hat Satellite 6 RedHat rubygem-pulp_python_client *
Red Hat Satellite 6 RedHat rubygem-pulp_rpm_client *
Red Hat Satellite 6 RedHat rubygem-puma *
Red Hat Satellite 6 RedHat rubygem-puma-status *
Red Hat Satellite 6 RedHat rubygem-raabro *
Red Hat Satellite 6 RedHat rubygem-rabl *
Red Hat Satellite 6 RedHat rubygem-rack *
Red Hat Satellite 6 RedHat rubygem-rack-cors *
Red Hat Satellite 6 RedHat rubygem-rack-jsonp *
Red Hat Satellite 6 RedHat rubygem-rack-protection *
Red Hat Satellite 6 RedHat rubygem-rack-test *
Red Hat Satellite 6 RedHat rubygem-rails *
Red Hat Satellite 6 RedHat rubygem-rails-dom-testing *
Red Hat Satellite 6 RedHat rubygem-rails-html-sanitizer *
Red Hat Satellite 6 RedHat rubygem-rails-i18n *
Red Hat Satellite 6 RedHat rubygem-railties *
Red Hat Satellite 6 RedHat rubygem-rainbow *
Red Hat Satellite 6 RedHat rubygem-rb-inotify *
Red Hat Satellite 6 RedHat rubygem-rbnacl *
Red Hat Satellite 6 RedHat rubygem-rbvmomi2 *
Red Hat Satellite 6 RedHat rubygem-rchardet *
Red Hat Satellite 6 RedHat rubygem-recursive-open-struct *
Red Hat Satellite 6 RedHat rubygem-redfish_client *
Red Hat Satellite 6 RedHat rubygem-redis *
Red Hat Satellite 6 RedHat rubygem-representable *
Red Hat Satellite 6 RedHat rubygem-responders *
Red Hat Satellite 6 RedHat rubygem-rest-client *
Red Hat Satellite 6 RedHat rubygem-retriable *
Red Hat Satellite 6 RedHat rubygem-rkerberos *
Red Hat Satellite 6 RedHat rubygem-roadie *
Red Hat Satellite 6 RedHat rubygem-roadie-rails *
Red Hat Satellite 6 RedHat rubygem-rsec *
Red Hat Satellite 6 RedHat rubygem-ruby2_keywords *
Red Hat Satellite 6 RedHat rubygem-ruby2ruby *
Red Hat Satellite 6 RedHat rubygem-rubyipmi *
Red Hat Satellite 6 RedHat rubygem-ruby-libvirt *
Red Hat Satellite 6 RedHat rubygem-ruby_parser *
Red Hat Satellite 6 RedHat rubygem-safemode *
Red Hat Satellite 6 RedHat rubygem-scoped_search *
Red Hat Satellite 6 RedHat rubygem-sd_notify *
Red Hat Satellite 6 RedHat rubygem-secure_headers *
Red Hat Satellite 6 RedHat rubygem-sequel *
Red Hat Satellite 6 RedHat rubygem-server_sent_events *
Red Hat Satellite 6 RedHat rubygem-sexp_processor *
Red Hat Satellite 6 RedHat rubygem-sidekiq *
Red Hat Satellite 6 RedHat rubygem-signet *
Red Hat Satellite 6 RedHat rubygem-sinatra *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_ansible *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_container_gateway *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_dhcp_infoblox *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_dhcp_remote_isc *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_discovery *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_discovery_image *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_dns_infoblox *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_dynflow *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_dynflow_core *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_openscap *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_pulp *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_remote_execution_ssh *
Red Hat Satellite 6 RedHat rubygem-smart_proxy_shellhooks *
Red Hat Satellite 6 RedHat rubygem-snaky_hash *
Red Hat Satellite 6 RedHat rubygem-spidr *
Red Hat Satellite 6 RedHat rubygem-sprockets *
Red Hat Satellite 6 RedHat rubygem-sprockets-rails *
Red Hat Satellite 6 RedHat rubygem-sqlite3 *
Red Hat Satellite 6 RedHat rubygem-sshkey *
Red Hat Satellite 6 RedHat rubygem-statsd-instrument *
Red Hat Satellite 6 RedHat rubygem-stomp *
Red Hat Satellite 6 RedHat rubygem-thor *
Red Hat Satellite 6 RedHat rubygem-tilt *
Red Hat Satellite 6 RedHat rubygem-timeliness *
Red Hat Satellite 6 RedHat rubygem-trailblazer-option *
Red Hat Satellite 6 RedHat rubygem-tzinfo *
Red Hat Satellite 6 RedHat rubygem-uber *
Red Hat Satellite 6 RedHat rubygem-unicode-display_width *
Red Hat Satellite 6 RedHat rubygem-validates_lengths_from_database *
Red Hat Satellite 6 RedHat rubygem-version_gem *
Red Hat Satellite 6 RedHat rubygem-webrick *
Red Hat Satellite 6 RedHat rubygem-websocket-driver *
Red Hat Satellite 6 RedHat rubygem-websocket-extensions *
Red Hat Satellite 6 RedHat rubygem-will_paginate *
Red Hat Satellite 6 RedHat rubygem-xmlrpc *
Red Hat Satellite 6 RedHat rubygem-zeitwerk *
Red Hat Satellite 6 RedHat satellite *
Red Hat Satellite 6 RedHat satellite-clone *
Red Hat Satellite 6 RedHat satellite-convert2rhel-toolkit *
Red Hat Satellite 6 RedHat satellite-installer *
Red Hat Satellite 6 RedHat satellite-lifecycle *
Red Hat Satellite 6 RedHat satellite-maintain *
Red Hat Satellite 6 RedHat yggdrasil-worker-forwarder *
RHODF-4.16-RHEL-9 RedHat odf4/mcg-core-rhel9:v4.16.0-60 *
RHODF-4.16-RHEL-9 RedHat odf4/ocs-client-console-rhel9:v4.16.2-2 *
RHODF-4.16-RHEL-9 RedHat odf4/odf-console-rhel9:v4.16.2-2 *
RHODF-4.16-RHEL-9 RedHat odf4/odf-multicluster-console-rhel9:v4.16.2-2 *
Node-tar Ubuntu esm-apps/focal *
Node-tar Ubuntu esm-apps/jammy *
Node-tar Ubuntu focal *
Node-tar Ubuntu jammy *
Node-tar Ubuntu mantic *
Node-tar Ubuntu upstream *

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References