Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8cvr-4rrf-f244

Опубликовано: 10 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.4

Описание

Infinite open connection causes OctoRPKI to hang forever

OctoRPKI (github.com/cloudflare/cfrpki/cmd/octorpki) does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

Patches

For more information

If you have any questions or comments about this advisory email us at security@cloudflare.com

Пакеты

Наименование

github.com/cloudflare/cfrpki

go
Затронутые версииВерсия исправления

< 1.4.0

1.4.0

EPSS

Процентиль: 72%
0.00735
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 4 лет назад

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

CVSS3: 4.4
nvd
около 4 лет назад

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

CVSS3: 4.4
debian
около 4 лет назад

OctoRPKI does not limit the length of a connection, allowing for a slo ...

EPSS

Процентиль: 72%
0.00735
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-400