DirectorySecurity Advisories
Sign In
Security Advisories

CGA-c9f2-4r4w-h29v

Published

Last updated

https://images.chainguard.dev/security/CGA-c9f2-4r4w-h29v
Package

octo-sts

Latest Update
Not affected
Aliases
  • CVE-2024-34079
  • GHSA-75r6-6jg8-pfcq

Severity

3.7

Low

CVSS V3

Summary

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

Description

Impact

This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service.

Patches

This vulnerability existed in the repository at HEAD, we will cut a 0.1.0 release with the fix.

Workarounds

None

References

None

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images