A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
Link | Tags |
---|---|
https://github.com/Seagate/cortx-s3server/issues/1037 | issue tracking exploit third party advisory |
https://github.com/Seagate/cortx-s3server/pull/1041 | issue tracking third party advisory |