PT-2023-33003 · Unknown · Eventing-Gitlab Cluster-Local Server
Published
2023-12-08
·
Updated
2023-12-08
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
eventing-gitlab cluster-local server versions prior to v1.11.3
eventing-gitlab cluster-local server versions prior to v1.12.1
Description
The issue arises because the eventing-gitlab cluster-local server does not set the
ReadHeaderTimeout variable, making it susceptible to a DDoS attack, specifically a Slowloris attack. This type of attack occurs when a large number of users send requests to the server, causing it to hang for an extended period and denying access to other users.Recommendations
For versions prior to v1.11.3, update to v1.11.3 to resolve the issue.
For versions prior to v1.12.1, update to v1.12.1 to resolve the issue.
As a temporary workaround, consider setting the
ReadHeaderTimeout variable to prevent the server from hanging due to Slowloris attacks. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eventing-Gitlab Cluster-Local Server