PublicCVE

CVE-2020-1722

MEDIUM5.3JSON exportCreate alert

Description

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected products

  • Red Hat / ipaall ipa versions 4.x.x through 4.8.0 – all ipa versions 4.x.x through 4.8.0