PT-2023-33003 · Unknown · Eventing-Gitlab Cluster-Local Server

Published

2023-12-08

·

Updated

2023-12-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions eventing-gitlab cluster-local server versions prior to v1.11.3 eventing-gitlab cluster-local server versions prior to v1.12.1
Description The issue arises because the eventing-gitlab cluster-local server does not set the ReadHeaderTimeout variable, making it susceptible to a DDoS attack, specifically a Slowloris attack. This type of attack occurs when a large number of users send requests to the server, causing it to hang for an extended period and denying access to other users.
Recommendations For versions prior to v1.11.3, update to v1.11.3 to resolve the issue. For versions prior to v1.12.1, update to v1.12.1 to resolve the issue. As a temporary workaround, consider setting the ReadHeaderTimeout variable to prevent the server from hanging due to Slowloris attacks.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-99JV-8292-2HPM

Affected Products

Eventing-Gitlab Cluster-Local Server