Red Hat Bugzilla – Bug 1087909
CVE-2014-0180 CFME: app/controllers/application_controller.rb wait_for_task DoS
Last modified: 2014-09-16 08:34:40 EDT
Jan Rusnacko of the Red Hat Product Security Team reports: Under certain circumstances wait_for_task CFME goes into an infinite loop calling wait_for_task for ~10 sec until it throws an exception. If called repeatedly an attacker can effectively DoS the server.
Acknowledgements: This issue was discovered by Jan Rusnacko of the Red Hat Product Security Team.
This issue has been addressed in following products: CloudForms Management Engine 5.x Via RHSA-2014:0816 https://rhn.redhat.com/errata/RHSA-2014-0816.html