漏洞标题
由于动态URL的递归爬取导致的WeGIA服务中断问题(DoS)
漏洞描述信息
WeGIA 是一个开源的Web管理系统,主要面向葡萄牙语用户。WeGIA中存在一个拒绝服务(DoS)漏洞。该漏洞允许任何未认证的用户通过执行激进的爬取操作使服务器变得无响应。此漏洞由递归爬取动态生成的URL和无法妥善处理大量请求引起。此漏洞在3.2.16版本中已得到修复。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
未加控制的资源消耗(资源穷尽)
漏洞标题
Denial of Service (DoS) in WeGIA due to Recursive Crawling of Dynamic URLs
漏洞描述信息
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS) vulnerability exists in WeGIA. This vulnerability allows any unauthenticated user to cause the server to become unresponsive by performing aggressive spidering. The vulnerability is caused by recursive crawling of dynamically generated URLs and insufficient handling of large volumes of requests. This vulnerability is fixed in 3.2.16.
CVSS信息
N/A
漏洞类别
不加限制或调节的资源分配