CVE-2024-34084
Last modified
CVE-2024-34084 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at the point of failure. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at the point of failure. This allows an attacker with the ability to send requests to `HandleGithubWebhook` to crash the Minder controlplane and deny other users from using it. This vulnerability is fixed in 0.0.48.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-34084?
How severe is CVE-2024-34084?
How do I fix CVE-2024-34084?
Are you affected by CVE-2024-34084?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
