PT-2023-16047 · Nlnet · Nlnet Labs Krill

Kittensaredabest

·

Published

2023-01-17

·

Updated

2023-01-25

·

CVE-2023-0158

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Krill versions prior to 0.12.1
Description The issue arises when a direct query is made for any existing directory under the "/rrdp/" endpoint, rather than an RRDP file, causing the server to crash. If the built-in "/rrdp" endpoint is exposed directly to the internet, malicious remote parties can exploit this to crash the publication server, affecting its availability but not the repository content itself.
Recommendations For versions prior to 0.12.1, update to version 0.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/rrdp" endpoint to prevent malicious queries from causing the server to crash.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-0158

Affected Products

Nlnet Labs Krill