« Volver al listado

CVE-2013-4599

Estado: ModificadaMedia (4.3)—

The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is set to a high value, allows remote attackers to cause a denial of service (process consumption) via multiple requests.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4599",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-06-09T19:55:09.600",
  "references": [
    {
      "url": "http://seclists.org/oss-sec/2013/q4/317",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/63705",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2134409",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2134413",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2135273",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/oss-sec/2013/q4/317",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/63705",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2134409",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2134413",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2135273",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the \"delay misery\" configuration is set to a high value, allows remote attackers to cause a denial of service (process consumption) via multiple requests."
    },
    {
      "lang": "es",
      "value": "El módulo Misery 6.x-2.x anterior a 6.x-2.5 y 7.x-2.x anterior a 7.x-2.2 para Drupal, cuando la configuración 'retrasar misery' está configurada a un valor alto, permite a atacanntes remotos causar una denegación de servicio (consumo de proceso) a través de solicitudes múltiples."
    }
  ],
  "lastModified": "2026-06-16T23:57:33.607",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.0:-:-:*:-:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1060C5B7-025B-432C-BF6B-2B0C25A74D87"
            },
            {
              "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.1:-:-:*:-:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5939A66-16DB-406B-9AD9-A48E6DA959EC"
            },
            {
              "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.2:-:-:*:-:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33DB7FE2-8788-4E0A-8F3F-931512BFED58"
            },
            {
              "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.3:-:-:*:-:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4632A5C6-B375-40BE-8BE6-B36456D35F58"
            },
            {
              "criteria": "cpe:2.3:a:misery_project:misery:6.x-2.4:-:-:*:-:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A990C479-179D-428E-8B52-E080D0BDE514"
            },
            {
              "criteria": "cpe:2.3:a:misery_project:misery:7.x-2.0:-:-:*:-:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "116313ED-5DFF-49F6-A533-A6D75F35CFD8"
            },
            {
              "criteria": "cpe:2.3:a:misery_project:misery:7.x-2.1:-:-:*:-:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A99CA68-2593-4E08-89C7-6177647EFE39"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}