Description
ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a malformed TimeProfile could be created causing later UI and API requests to timeout leading to a Denial of Service. Version radjabov-2 contains a patch. One may also apply the patch manually.
Problem types
CWE-20: Improper Input Validation
Product status
References
github.com/...nageiq/security/advisories/GHSA-m832-x3g8-63j3
github.com/...79cef10c7d0278d8a37c3f547c426948180df4df.patch
github.com/...ommit/86132851257d73ed9e31a88315e47a8a2b838113