Описание
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
Ссылки
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.17.1 (исключая)
cpe:2.3:a:protocol:libp2p:*:*:*:*:*:rust:*:*
EPSS
Процентиль: 21%
0.00285
Низкий
8.2 High
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 8.2
github
4 месяца назад
libp2p-rendezvous: Unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
CVSS3: 8.2
fstec
4 месяца назад
Уязвимость сервера библиотеки libp2p-rust, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
Процентиль: 21%
0.00285
Низкий
8.2 High
CVSS3
Дефекты
CWE-770