ISC Stork
cpe:2.3:a:isc:stork:*:*:*:*:*:*:*
- >= 1.0.0, <= 2.3.0
A denial-of-service vulnerability has been identified in ISC Stork versions 1.0.0 prior to 2.3.0. The issue arises when an unauthenticated user sends a large volume of data to the Stork UI, potentially leading to memory and disk usage problems on the server running Stork.
Exploitation of this vulnerability causes resource exhaustion, where excessive input leads Stork to use more memory than available. This can cause the 'stork-server' process, or other processes, to fail. Additionally, smaller inputs may not fully exhaust memory but can fill log storage or trigger premature log rotation.
Users can upgrade to Stork versions 2.2.1 or 2.3.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.