PT-2023-16047 · Nlnet · Nlnet Labs Krill
Kittensaredabest
·
Published
2023-01-17
·
Updated
2023-01-25
·
CVE-2023-0158
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Krill versions prior to 0.12.1
Description
The issue arises when a direct query is made for any existing directory under the "/rrdp/" endpoint, rather than an RRDP file, causing the server to crash. If the built-in "/rrdp" endpoint is exposed directly to the internet, malicious remote parties can exploit this to crash the publication server, affecting its availability but not the repository content itself.
Recommendations
For versions prior to 0.12.1, update to version 0.12.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "/rrdp" endpoint to prevent malicious queries from causing the server to crash.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nlnet Labs Krill