PT-2024-29978 · Unknown · Skyport Daemon

Published

2024-08-12

·

Updated

2024-09-16

·

CVE-2024-42481

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Skyport Daemon versions prior to 0.2.2
Description The issue is related to the Skyport Daemon (skyportd), which is the daemon for the Skyport Panel. It can be exploited by creating thousands of folders and files, taking advantage of the lack of rate limiting on createFolder and createFile functions. This can cause 100% CPU usage and an Out-of-Memory (OOM) condition, potentially crashing the system.
Recommendations For versions prior to 0.2.2, update to version 0.2.2 to resolve the issue. As a temporary workaround, consider restricting the use of the createFolder and createFile functions to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-42481
GHSA-CWMQ-PHCX-9G92

Affected Products

Skyport Daemon