CVE-2026-28342
中文标题:
(暂无数据)
英文标题:
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2,
漏洞描述
中文描述:
(暂无数据)
英文描述:
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing requests. By issuing multiple parallel requests, an attacker can exhaust available container memory, leading to service degradation or complete denial of service (DoS). The issue occurs because the endpoint performs computationally and memory-intensive hashing operations without request throttling, authentication requirements, or resource limits. This issue has been patched in version 3000.10.2.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| olivetin | olivetin | * | - | - |
cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| NVD | nvd_CVE-2026-28342 |
2026-03-06 02:00:04 | 2026-03-05 22:00:03 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 0 -> 1