pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://www.percona.com/doc/percona-monitoring-and-management/2.x/release-notes/2.2.1.html | release notes vendor advisory |
https://jira.percona.com/browse/PMM-5233 | third party advisory |
https://jira.percona.com/browse/PMM-5232 | third party advisory patch |
https://www.percona.com/blog/2020/02/03/improvements-in-pmm-bug-fixes-in-percona-server-percona-backup-for-mongodb-alert-release-roundup-2-3-2020/ | vendor advisory |