Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS05OWp2LTgyOTItMmhwbc4AA3pg
eventing-gitlab vulnerable to denial of service, caused by improper enforcement of the timeout on individual read operations
Impact
The eventing-gitlab cluster-local server doesn't set ReadHeaderTimeout
which could lead do a DDoS attack, where a large group of users send requests to the server causing the server to hang for long enough to deny it from being available to other users, also know as a Slowloris attack.
Patches
Fix in v1.12.1
and v1.11.3
.
Credits
The vulnerability was reported by Ada Logics during an ongoing security audit of Knative involving Ada Logics, the Knative maintainers, OSTIF and CNCF.
Permalink: https://github.com/advisories/GHSA-99jv-8292-2hpmJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05OWp2LTgyOTItMmhwbc4AA3pg
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: 12 months ago
Updated: 12 months ago
Identifiers: GHSA-99jv-8292-2hpm
References:
- https://github.com/knative-extensions/eventing-gitlab/security/advisories/GHSA-99jv-8292-2hpm
- https://github.com/knative-extensions/eventing-gitlab/commit/463fcb36ac31cdac34eda0e900b64039d6d30b36
- https://github.com/knative-extensions/eventing-gitlab/commit/db76c668aa47890e7fe73c9df3135da292cfd9ec
- https://github.com/advisories/GHSA-99jv-8292-2hpm
Blast Radius: 0.0
Affected Packages
go:knative.dev/eventing-gitlab
Dependent packages: 1Dependent repositories: 5
Downloads:
Affected Version Ranges: <= 0.39.0
No known fixed version
All affected versions: 0.18.0, 0.18.1, 0.19.0, 0.20.0, 0.21.0, 0.22.0, 0.22.1, 0.23.0, 0.23.1, 0.23.2, 0.24.0, 0.24.1, 0.25.0, 0.25.1, 0.26.0, 0.27.0, 0.28.0, 0.29.0, 0.30.0, 0.30.1, 0.31.0, 0.32.0, 0.33.0, 0.34.0, 0.35.0, 0.36.0, 0.36.1, 0.37.0, 0.37.1, 0.37.2, 0.38.0, 0.38.1, 0.38.2, 0.38.3, 0.39.0