CVE-2024-34084

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-34084
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-34084.json
Aliases
Published
2024-05-07T15:15:09Z
Modified
2024-05-14T13:11:27.234263Z
Summary
[none]
Details

Minder's HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at the point of failure. This allows an attacker with the ability to send requests to HandleGithubWebhook to crash the Minder controlplane and deny other users from using it. This vulnerability is fixed in 0.0.48.

References

Affected packages

Git / github.com/stacklok/minder

Affected ranges

Type
GIT
Repo
https://github.com/stacklok/minder
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

v0.*

v0.0.1
v0.0.10
v0.0.11
v0.0.12
v0.0.13
v0.0.14
v0.0.15
v0.0.16
v0.0.17
v0.0.18
v0.0.19
v0.0.2
v0.0.20
v0.0.21
v0.0.22
v0.0.23
v0.0.24
v0.0.25
v0.0.26
v0.0.27
v0.0.28
v0.0.29
v0.0.3
v0.0.30
v0.0.31
v0.0.32
v0.0.33
v0.0.34
v0.0.35
v0.0.36
v0.0.37
v0.0.38
v0.0.39
v0.0.4
v0.0.40
v0.0.41
v0.0.42
v0.0.43
v0.0.44
v0.0.45
v0.0.46
v0.0.47
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9