2024-12-08 03:06:42 +00:00

72 lines
2.5 KiB
JSON

{
"id": "CVE-2024-34079",
"sourceIdentifier": "security-advisories@github.com",
"published": "2024-05-14T15:38:29.183",
"lastModified": "2024-11-21T09:18:02.823",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0"
},
{
"lang": "es",
"value": "octo-sts es una aplicaci\u00f3n de GitHub que act\u00faa como un servicio de token de seguridad (STS) para la API de Github. Esta vulnerabilidad puede aumentar la utilizaci\u00f3n de recursos del servicio STS y, combinada con un volumen de tr\u00e1fico significativo, podr\u00eda provocar una denegaci\u00f3n de servicio. Esta vulnerabilidad se solucion\u00f3 en 0.1.0."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"baseScore": 3.7,
"baseSeverity": "LOW",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.2,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"references": [
{
"url": "https://github.com/octo-sts/app/commit/74ba874c017cf973edd6711144cf4399a9fcff57",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/octo-sts/app/security/advisories/GHSA-75r6-6jg8-pfcq",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/octo-sts/app/commit/74ba874c017cf973edd6711144cf4399a9fcff57",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/octo-sts/app/security/advisories/GHSA-75r6-6jg8-pfcq",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}