#VU64571 Allocation of Resources Without Limits or Throttling in Uyuni SUSE Manager - CVE-2022-21952
Published: June 22, 2022
Uyuni SUSE Manager
Uyuni Project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the "/rhn/manager/frontend-log" script takes a text as a POST parameter and then it writes into the "/var/log/rhn/rhn_web_frontend.log" file. A remote non-authenticated attacker can send arbitrary amount of data to the application log and consume all available disk space, cause a denial of service condition.