{"id":"GHSA-99jv-8292-2hpm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-99jv-8292-2hpm","summary":"eventing-gitlab vulnerable to denial of service, caused by improper enforcement of the timeout on individual read operations","details":"### Impact\n\nThe eventing-gitlab cluster-local server doesn't set `ReadHeaderTimeout`‬‭ which could lead do a DDoS‬ ‭attack, where a large group of users send requests to the server causing the server to hang‬ ‭for long enough to deny it from being available to other users, also know as a Slowloris‬ ‭attack.\n\n### Patches\n\nFix in `v1.12.1` and `v1.11.3`.\n\n\n### Credits\n\nThe vulnerability was reported by Ada Logics during an ongoing security audit of Knative involving Ada Logics, the Knative maintainers, OSTIF and CNCF.\n","published":"2023-12-08T21:57:27Z","modified":"2023-12-08T21:57:27Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"knative.dev/eventing-gitlab","fixedVersion":null}],"fix":{"url":"https://github.com/knative-extensions/eventing-gitlab/commit/463fcb36ac31cdac34eda0e900b64039d6d30b36","label":"knative-extensions/eventing-gitlab@463fcb3"},"references":[{"type":"WEB","url":"https://github.com/knative-extensions/eventing-gitlab/security/advisories/GHSA-99jv-8292-2hpm"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-gitlab/commit/463fcb36ac31cdac34eda0e900b64039d6d30b36"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-gitlab/commit/db76c668aa47890e7fe73c9df3135da292cfd9ec"},{"type":"PACKAGE","url":"https://github.com/knative-extensions/eventing-gitlab"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-12-08T21:57:27Z"}}