{"id":"GHSA-v7hc-87jc-qrrr","summary":"eventing-github vulnerable to denial of service caused by improper enforcement of the timeout on individual read operations","details":"### Impact\n\nThe eventing-github cluster-local server doesn't set `ReadHeaderTimeout`\u202c\u202d which could lead do a DDoS\u202c \u202dattack, where a large group of users send requests to the server causing the server to hang\u202c \u202dfor long enough to deny it from being available to other users, also know as a Slowloris\u202c \u202dattack.\n\n### Patches\n\nFix in `v1.12.1` and `v1.11.3`\n\n### Credits\n\nThe vulnerability was reported by Ada Logics during an ongoing security audit of Knative involving Ada Logics, the Knative maintainers, OSTIF and CNCF.\n","aliases":["GO-2023-2388"],"modified":"2024-08-21T14:57:07.620437Z","published":"2023-12-06T19:19:35Z","database_specific":{"cwe_ids":["CWE-400"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-12-06T19:19:35Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/security/advisories/GHSA-v7hc-87jc-qrrr"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/442"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/446"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/447"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/commit/ea5cb8b25fc3410dde45ce2eb95454e4cfe77c40"},{"type":"PACKAGE","url":"https://github.com/knative-extensions/eventing-github"}],"affected":[{"package":{"name":"knative.dev/eventing-github","ecosystem":"Go","purl":"pkg:golang/knative.dev/eventing-github"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.39.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-v7hc-87jc-qrrr/GHSA-v7hc-87jc-qrrr.json"}}],"schema_version":"1.9.0"}