VDB
Sign up
LOW3.7

GHSA-75r6-6jg8-pfcq

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

Quick fix

GHSA-75r6-6jg8-pfcq — github.com/octo-sts/app: upgrade to the fixed version with the command below.

go get github.com/octo-sts/app@v0.1.0

Details

### Impact This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service.

### Patches This vulnerability existed in the repository at HEAD, we will cut a 0.1.0 release with the fix.

### Workarounds None

### References None

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/octo-sts/app
Introduced in: 0Fixed in: 0.1.0
Fixgo get github.com/octo-sts/app@v0.1.0

References