Skip to content

v4 API Excessive log data DOS

High
jack7anderson7 published GHSA-jrpp-22g3-2j77 Jun 10, 2024

Package

SuiteCRM

Affected versions

<= 7.14.3
<= 8.6.0

Patched versions

7.14.4
8.6.1

Description

Impact

What kind of vulnerability is it? Who is impacted?

  • Deprecated v4 API example with no log rotation allows DOS by logging excessive data

Patches

Has the problem been patched? What versions should users upgrade to?

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

  • Block access to service/example/ directory from the webserver, using .htaccess or other configuration

References

Are there any links users can visit to find out more?

Severity

High
8.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CVE ID

CVE-2024-36416

Weaknesses

Credits