PT-2023-25879 · Faktory · Faktory

Malayke

·

Publicado

2023-09-20

·

Atualizado

2024-08-21

·

CVE-2023-37279

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Faktory versions prior to 1.8.0
Description The Faktory web dashboard can suffer from denial of service by a crafted malicious URL query parameter days. This issue is related to how the backend reads the days URL query parameter in the Faktory web dashboard. The value is used directly without any checks to create a string slice. If a very large value is provided, the backend server ends up using a significant amount of memory and causing it to crash.
Recommendations For versions prior to 1.8.0, update to version 1.8.0 to resolve the issue. As a temporary workaround, consider restricting access to the Faktory web dashboard to minimize the risk of exploitation. Avoid using the days parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37279
GHSA-X4HH-VJM7-G2JV
GO-2023-2067

Produtos afetados

Faktory