{"id":"GHSA-v7hc-87jc-qrrr","aliases":["GO-2023-2388"],"url":"https://o3.security/vulnerability/GHSA-v7hc-87jc-qrrr","summary":"eventing-github vulnerable to denial of service caused by improper enforcement of the timeout on individual read operations","details":"### Impact\n\nThe eventing-github cluster-local server doesn't set `ReadHeaderTimeout`‬‭ which could lead do a DDoS‬ ‭attack, where a large group of users send requests to the server causing the server to hang‬ ‭for long enough to deny it from being available to other users, also know as a Slowloris‬ ‭attack.\n\n### Patches\n\nFix in `v1.12.1` and `v1.11.3`\n\n### Credits\n\nThe vulnerability was reported by Ada Logics during an ongoing security audit of Knative involving Ada Logics, the Knative maintainers, OSTIF and CNCF.\n","published":"2023-12-06T19:19:35Z","modified":"2024-08-21T14:57:07.620437Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"knative.dev/eventing-github","fixedVersion":"0.39.1"}],"fix":{"url":"https://github.com/knative-extensions/eventing-github/pull/442","label":"knative-extensions/eventing-github#442"},"references":[{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/security/advisories/GHSA-v7hc-87jc-qrrr"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/442"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/446"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/447"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/commit/ea5cb8b25fc3410dde45ce2eb95454e4cfe77c40"},{"type":"PACKAGE","url":"https://github.com/knative-extensions/eventing-github"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-21T14:57:07.620437Z"}}