Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at the point of failure. This allows an attacker with the ability to send requests to `HandleGithubWebhook` to crash the Minder controlplane and deny other users from using it. This vulnerability is fixed in 0.0.48.
References
Configurations
No configuration.
History
21 Nov 2024, 09:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/stacklok/minder/commit/3e5a527d2f1b535159206161d1d519602c75bd0d - | |
References | () https://github.com/stacklok/minder/security/advisories/GHSA-9c5w-9q3f-3hv7 - |
07 May 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-07 15:15
Updated : 2024-11-21 09:18
NVD link : CVE-2024-34084
Mitre link : CVE-2024-34084
CVE.ORG link : CVE-2024-34084
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption