PT-2024-25689 · Octo-Sts · Octo-Sts

Enj

·

Published

2024-05-10

·

Updated

2025-11-26

·

CVE-2024-34079

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions octo-sts versions prior to 0.1.0
Description The issue can cause a spike in resource utilization of the STS service. When combined with significant traffic volume, it could potentially lead to a denial of service. Excessively large requests can be processed, consuming a large amount of resources.
Recommendations For versions prior to 0.1.0, update to version 0.1.0 to resolve the issue. As a temporary workaround, consider restricting the size of requests processed by the STS service to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34079
GHSA-75R6-6JG8-PFCQ
GO-2024-2833

Affected Products

Octo-Sts