CVE-2017-11468
docker-distribution: Does not properly restrict the amount of content accepted from a user
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
Docker Registry anterior a versiĆ³n 2.6.2 en Docker Distribution, no restringe apropiadamente la cantidad de contenido aceptado por un usuario, lo que permite a los atacantes remotos causar una denegaciĆ³n de servicio (consumo de memoria) por medio un endpoint manifest.
It was found that docker-distribution did not properly restrict memory allocation size for a registry instance through the manifest endpoint. An attacker could send a specially crafted request that would exhaust the memory of the docker-distribution service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-19 CVE Reserved
- 2017-07-20 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/docker/distribution/pull/2340 | Third Party Advisory | |
https://github.com/docker/distribution/releases/tag/v2.6.2 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00047.html | 2023-01-20 | |
https://access.redhat.com/errata/RHSA-2017:2603 | 2023-01-20 | |
https://access.redhat.com/security/cve/CVE-2017-11468 | 2017-09-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1474893 | 2017-09-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Docker Search vendor "Docker" | Docker Registry Search vendor "Docker" for product "Docker Registry" | <= 2.6.1 Search vendor "Docker" for product "Docker Registry" and version " <= 2.6.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 7.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "7.0" | - |
Affected
|