{"id":"GHSA-p2gm-ffr3-w2xw","summary":"Nervos CKB vulnerable to low-resource flood DDoS attacks through network message","details":"### Workarounds\n* forbid request genesis through network request\n* forbid requesting duplicate data  through network request\n\n","modified":"2023-02-08T18:17:06Z","published":"2023-02-08T18:17:06Z","database_specific":{"cwe_ids":[],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-02-08T18:17:06Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/nervosnetwork/ckb/security/advisories/GHSA-p2gm-ffr3-w2xw"},{"type":"PACKAGE","url":"https://github.com/nervosnetwork/ckb"}],"affected":[{"package":{"name":"ckb","ecosystem":"crates.io","purl":"pkg:cargo/ckb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.101.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-p2gm-ffr3-w2xw/GHSA-p2gm-ffr3-w2xw.json"}}],"schema_version":"1.9.0"}