/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-34079

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-34079

CGA ID

CGA-c9f2-4r4w-h29v

Severity

3.7

Low

CVSS V3

Description

octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0

References

  • https://images.chainguard.dev/security/CGA-c9f2-4r4w-h29v

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images